Utopiasoftware has a narrowly scoped vulnerability footprint centered on its News Pro product, where the durable signal centers on cross-site request forgery weaknesses in web-facing functionality. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Utopiasoftware over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4325MEDIUM Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrator | Aug 14, 2012 | 6.8 | 30 | NO | YES |
CVE-2005-3201HIGH SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbit | Oct 14, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-3200MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle par | Oct 14, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-4223HIGH Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in edi | Dec 14, 2005 | 7.5 | 20 | NO | NO |
Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter. | Jun 19, 2007 | 2.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Utopiasoftware.
Media articles that mention a CVE ID that affects a product developed by Utopiasoftware — matched by CVE ID, not by vendor name.