Known Vulnerabilities for products from Nexusphp Project
Listed below are 16 of the newest known vulnerabilities associated with the vendor "Nexusphp Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2017-15305 json | XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php. | 6.1 - MEDIUM | 2017-10-15 | 2017-10-25 |
| CVE-2017-14534 json | Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF. | 6.1 - MEDIUM | 2017-09-18 | 2017-09-21 |
| CVE-2017-14512 json | NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different v... | 9.8 - CRITICAL | 2017-09-17 | 2017-09-21 |
| CVE-2017-14347 json | NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action. | 6.1 - MEDIUM | 2017-09-12 | 2017-09-16 |
| CVE-2017-12910 json | SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the... | 9.8 - CRITICAL | 2017-08-17 | 2017-08-20 |
| CVE-2017-12909 json | SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the ... | 9.8 - CRITICAL | 2017-08-17 | 2017-08-20 |
| CVE-2017-12908 json | SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via ... | 9.8 - CRITICAL | 2017-08-17 | 2017-08-20 |
| CVE-2017-12907 json | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php. | 6.1 - MEDIUM | 2017-08-17 | 2017-08-20 |
| CVE-2017-12906 json | Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML... | 6.1 - MEDIUM | 2017-09-07 | 2017-09-13 |
| CVE-2017-12838 json | Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users... | 8.8 - HIGH | 2017-09-07 | 2017-09-13 |
| CVE-2017-12798 json | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php. | 6.1 - MEDIUM | 2017-08-10 | 2017-08-18 |
| CVE-2017-12792 json | Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authenticatio... | 6.1 - MEDIUM | 2017-10-03 | 2017-10-13 |
| CVE-2017-12777 json | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php. | 6.1 - MEDIUM | 2017-08-09 | 2017-08-30 |
| CVE-2017-12776 json | SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the ... | 9.8 - CRITICAL | 2017-08-18 | 2017-09-19 |
| CVE-2017-12680 json | Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php. | 6.1 - MEDIUM | 2017-08-18 | 2017-08-23 |
| CVE-2017-12655 json | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action. | Not Provided | 2017-08-07 | 2025-04-20 |