Tribiq's vulnerability profile concentrates in a single content-management system product that has attracted significant public exploit tooling development despite a modest overall CVE volume. The recurring weaknesses—path traversal, cross-site scripting, SQL injection, sensitive information exposure, and authentication flaws—are characteristic of web application attack surfaces and reflect common input-handling and access-control gaps in CMS implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tribiq over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5312HIGH SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | Oct 8, 2012 | 7.5 | 33 | NO | YES |
CVE-2008-6804HIGH Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NO | May 11, 2009 | 7.5 | 30 | NO | YES |
CVE-2009-2220MEDIUM Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and possibl | Jun 26, 2009 | 5.1 | 23 | NO | YES |
CVE-2008-4894MEDIUM Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled and magic_quotes_gpc is | Nov 4, 2008 | 5.1 | 23 | NO | YES |
CVE-2008-5960HIGH SQL injection vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to execute arbitrary SQL commands via the cID parameter in a document a | Jan 23, 2009 | 7.5 | 19 | NO | NO |
CVE-2011-2727MEDIUM The (1) templatewrap/templatefoot.php, (2) cmsjs/plugin.js.php, and (3) cmsincludes/cms_plugin_api_link.inc.php scripts in Tribal Tribiq CMS before 5.2.7c allow remote attackers to | Dec 30, 2014 | 4.3 | 18 | NO | NO |
Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled, allows remote at | Nov 4, 2008 | 2.6 | 18 | NO | YES |
CVE-2008-5961MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to inject arbitrary web script or HTML via the cID paramet | Jan 23, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tribiq.
Media articles that mention a CVE ID that affects a product developed by Tribiq — matched by CVE ID, not by vendor name.