Webspell is a web-based community and content-management platform whose vulnerability profile, despite a narrow product focus, occupies a notable position in the landscape due to its widespread deployment across smaller hosting and community sites. The recurring exposure centers on classic web-application weaknesses including cross-site scripting, SQL injection, cross-site request forgery, and improper authentication—flaws endemic to the platform's age and reliance on legacy code patterns that have repeatedly been targets for weaponization and public-tool development. While the severity profile of individual disclosures does not skew toward critical outcomes, the weakness classes themselves have a strong, recurring history of acquiring public exploit tooling, making instances attractive to lower-skill threat actors and automated scanning. Defenders running or hosting this platform should prioritize input-validation and authentication hardening; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webspell over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4861HIGH SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands via the search parameter. | Oct 5, 2011 | 7.5 | 32 | NO | YES |
CVE-2009-1912MEDIUM Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot do | Jun 4, 2009 | 6.8 | 30 | NO | YES |
CVE-2007-0502HIGH SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0 | Jan 25, 2007 | 7.5 | 30 | NO | YES |
CVE-2007-2369MEDIUM Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows remote attackers to read arbitrary files via a .. (dot dot) | Apr 30, 2007 | 5.0 | 28 | NO | YES |
CVE-2007-1163HIGH SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector t | Mar 2, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-5388HIGH SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the getsquad parameter, a different vector th | Oct 18, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-0728HIGH SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter. | Feb 16, 2006 | 7.5 | 28 | NO | YES |
CVE-2007-1019MEDIUM SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the showonly parameter | Feb 21, 2007 | 6.8 | 26 | NO | YES |
CVE-2007-1160HIGH webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a different vulnerability than CVE-2006-4782. | Mar 2, 2007 | 10.0 | 25 | NO | NO |
CVE-2006-4782MEDIUM src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive information stored in the datab | Sep 14, 2006 | 5.4 | 24 | NO | YES |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webspell.
Media articles that mention a CVE ID that affects a product developed by Webspell — matched by CVE ID, not by vendor name.