Known Vulnerabilities for products from Nexusphp Project

Listed below are 16 of the newest known vulnerabilities associated with the vendor "Nexusphp Project".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2017-15305 json XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php. 6.1 - MEDIUM 2017-10-15 2017-10-25
CVE-2017-14534 json Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF. 6.1 - MEDIUM 2017-09-18 2017-09-21
CVE-2017-14512 json NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different v... 9.8 - CRITICAL 2017-09-17 2017-09-21
CVE-2017-14347 json NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action. 6.1 - MEDIUM 2017-09-12 2017-09-16
CVE-2017-12910 json SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the... 9.8 - CRITICAL 2017-08-17 2017-08-20
CVE-2017-12909 json SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the ... 9.8 - CRITICAL 2017-08-17 2017-08-20
CVE-2017-12908 json SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via ... 9.8 - CRITICAL 2017-08-17 2017-08-20
CVE-2017-12907 json Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php. 6.1 - MEDIUM 2017-08-17 2017-08-20
CVE-2017-12906 json Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML... 6.1 - MEDIUM 2017-09-07 2017-09-13
CVE-2017-12838 json Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users... 8.8 - HIGH 2017-09-07 2017-09-13
CVE-2017-12798 json Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php. 6.1 - MEDIUM 2017-08-10 2017-08-18
CVE-2017-12792 json Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authenticatio... 6.1 - MEDIUM 2017-10-03 2017-10-13
CVE-2017-12777 json Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php. 6.1 - MEDIUM 2017-08-09 2017-08-30
CVE-2017-12776 json SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the ... 9.8 - CRITICAL 2017-08-18 2017-09-19
CVE-2017-12680 json Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php. 6.1 - MEDIUM 2017-08-18 2017-08-23
CVE-2017-12655 json Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action. Not Provided 2017-08-07 2025-04-20

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report