Webinsta's vulnerability profile concentrates in a narrow portfolio of web-based content management and mailing systems, a modest footprint within the broader web-application landscape. The recurring weakness classes center on information disclosure and code-injection flaws characteristic of server-side web applications, and its disclosures have frequently acquired public exploit code, warranting close attention to patch availability and deployment. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webinsta over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4209HIGH PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path | Aug 17, 2006 | 7.5 | 35 | NO | YES |
CVE-2006-4196HIGH PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the templates_dir | Aug 17, 2006 | 7.5 | 32 | NO | YES |
CVE-2006-4217HIGH PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir par | Aug 17, 2006 | 7.5 | 28 | NO | YES |
CVE-2007-2181MEDIUM PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_ | Apr 24, 2007 | 6.8 | 27 | NO | YES |
CVE-2005-0748HIGH PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path pa | Mar 10, 2005 | 7.5 | 19 | NO | NO |
CVE-2011-3816MEDIUM WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error mess | Sep 24, 2011 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webinsta.
Media articles that mention a CVE ID that affects a product developed by Webinsta — matched by CVE ID, not by vendor name.