Xampp is a lightweight, cross-platform Apache distribution bundle designed for local development and testing environments, with a narrow product scope centered on bundled server components. The vendor's disclosed vulnerabilities reflect the composition of its distribution rather than novel flaws in custom code, with characterizations often falling into broad or placeholder categories. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xampp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2079HIGH The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows remote attackers to t | Apr 18, 2007 | 9.3 | 37 | NO | YES |
CVE-2005-1078HIGH XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges. | Apr 12, 2005 | 7.5 | 30 | NO | YES |
CVE-2007-2080HIGH Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL commands via unspecified vectors in certain test scripts. | Apr 18, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-1077MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phoneb | Apr 12, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-2043MEDIUM Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php. | Jun 17, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xampp.
Media articles that mention a CVE ID that affects a product developed by Xampp — matched by CVE ID, not by vendor name.