Utopia Software maintains a narrowly focused product line centered on its news aggregation and publishing applications, which represent a modest attack surface in the vulnerability landscape. The observed disclosures cluster around the News Pro product family and involve miscellaneous or unclassified weakness categories; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Utopia Software over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4325MEDIUM Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrator | Aug 14, 2012 | 6.8 | 30 | NO | YES |
CVE-2005-3201HIGH SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbit | Oct 14, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-3200MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle par | Oct 14, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-4223HIGH Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in edi | Dec 14, 2005 | 7.5 | 20 | NO | NO |
Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter. | Jun 19, 2007 | 2.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Utopia Software.
Media articles that mention a CVE ID that affects a product developed by Utopia Software — matched by CVE ID, not by vendor name.