Known Vulnerabilities for products from Cutephp
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Cutephp".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-5558 json | CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. | 8.8 - HIGH | 2020-03-25 | 2021-07-21 |
| CVE-2020-5557 json | Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspe... | 6.1 - MEDIUM | 2020-03-25 | 2020-03-26 |
| CVE-2019-11447 json | An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in... | 8.8 - HIGH | 2019-04-22 | 2020-09-11 |
| CVE-2009-4250 json | Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attac... | Not Provided | 2009-12-10 | 2026-04-23 |
| CVE-2009-4249 json | Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quo... | Not Provided | 2009-12-10 | 2026-04-23 |
| CVE-2009-4175 json | CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid da... | Not Provided | 2009-12-02 | 2026-04-23 |
| CVE-2009-4174 json | The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote ... | Not Provided | 2009-12-02 | 2026-04-23 |
| CVE-2009-4173 json | Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attacker... | Not Provided | 2009-12-02 | 2026-04-23 |
| CVE-2009-4172 json | Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quote... | Not Provided | 2009-12-02 | 2026-04-23 |
| CVE-2009-4116 json | Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote authe... | Not Provided | 2009-11-30 | 2026-04-23 |
| CVE-2009-4115 json | Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated ... | Not Provided | 2009-11-30 | 2026-04-23 |
| CVE-2009-4113 json | Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows re... | Not Provided | 2009-11-30 | 2026-04-23 |
| CVE-2008-4557 json | plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbit... | Not Provided | 2008-10-14 | 2026-04-23 |
| CVE-2007-6662 json | Directory traversal vulnerability in file.php in CuteNews 2.6 allows remote attackers to read arbitrary files via a .. (dot d... | Not Provided | 2008-01-04 | 2026-04-23 |
| CVE-2007-1153 json | Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP ... | Not Provided | 2007-03-02 | 2026-04-23 |
| CVE-2006-6300 json | Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via... | Not Provided | 2006-12-05 | 2026-04-23 |
| CVE-2006-4445 json | ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitr... | 7.5 - HIGH | 2006-08-29 | 2023-11-07 |
| CVE-2006-3661 json | Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web scrip... | 2.6 - LOW | 2006-07-18 | 2008-09-05 |
| CVE-2006-2250 json | CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /... | Not Provided | 2006-05-09 | 2025-04-03 |
| CVE-2006-2249 json | Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow re... | Not Provided | 2006-05-09 | 2025-04-03 |
Known software with vulnerabilities from Cutephp
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Cutephp | Cutenews | 1.5.0.1 |