Webportal develops a focused content-management system product that exhibits a durable signal centered on application-layer injection vulnerabilities, specifically SQL injection and code injection flaws that arise from inadequate input sanitization and control-flow handling. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webportal over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1444HIGH PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. | Apr 27, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-4345HIGH SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter. | Sep 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-0142MEDIUM Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecifie | Jan 8, 2008 | 6.8 | 28 | NO | YES |
CVE-2007-6664HIGH SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter. | Jan 4, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webportal.
Media articles that mention a CVE ID that affects a product developed by Webportal — matched by CVE ID, not by vendor name.