Ttcms is a modest content management and forum platform whose vulnerability footprint centers on input-handling and code-execution flaws spanning its TTForum and TTCMS products. The durable signal reflects application-layer risks including SQL injection, code injection, and related input-validation weaknesses that are typical of web-based content platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ttcms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1459MEDIUM Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) i | Dec 31, 2003 | 6.8 | 31 | NO | YES |
CVE-2007-1708HIGH PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. | Mar 27, 2007 | 7.5 | 30 | NO | YES |
CVE-2003-0331HIGH SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Prefe | Jun 9, 2003 | 10.0 | 25 | NO | NO |
CVE-2003-1458HIGH SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name. | Dec 31, 2003 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ttcms.
Media articles that mention a CVE ID that affects a product developed by Ttcms — matched by CVE ID, not by vendor name.