Known Vulnerabilities for products from Phpkit

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Phpkit".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2016-10758 json PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/defa... 8.8 - HIGH 2019-05-24 2019-05-29
CVE-2015-1052 json Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject... Not Provided 2015-01-15 2026-05-06
CVE-2008-7193 json PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSR... Not Provided 2009-09-09 2026-04-23
CVE-2007-6134 json SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL c... Not Provided 2007-11-27 2026-04-23
CVE-2007-0179 json SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via t... Not Provided 2007-01-11 2026-04-23
CVE-2006-7115 json SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parame... Not Provided 2007-03-06 2026-04-23
CVE-2006-1773 json SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary... Not Provided 2006-04-13 2025-04-03
CVE-2006-1507 json Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via ... Not Provided 2006-03-30 2025-04-03
CVE-2006-0786 json Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows... Not Provided 2006-02-19 2025-04-03
CVE-2006-0785 json Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include... Not Provided 2006-02-19 2025-04-03
CVE-2005-4424 json Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary ... Not Provided 2005-12-20 2025-04-03
CVE-2005-3554 json Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled... Not Provided 2005-11-16 2025-04-03
CVE-2005-3553 json Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitr... Not Provided 2005-11-16 2025-04-03
CVE-2005-3552 json Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary... Not Provided 2005-11-16 2025-04-03
CVE-2005-2699 json Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execu... Not Provided 2005-08-26 2025-04-03
CVE-2005-2683 json Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) l... Not Provided 2005-08-23 2025-04-03
CVE-2004-1879 json Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HT... Not Provided 2004-12-31 2025-04-03
CVE-2004-1538 json SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL co... Not Provided 2004-12-31 2025-04-03
CVE-2004-1537 json Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbit... Not Provided 2004-12-31 2025-04-03
CVE-2003-1187 json Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitra... Not Provided 2003-11-02 2025-04-03

Known software with vulnerabilities from Phpkit

Type Vendor Product Version
ApplicationPhpkitPhpkit1.6.6

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report