Known Vulnerabilities for products from Stphp
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Stphp".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2007-3331 json | Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin passwor... | Not Provided | 2007-06-21 | 2026-04-23 |
| CVE-2007-3330 json | Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to inject arbitrary web script or ... | Not Provided | 2007-06-21 | 2026-04-23 |
| CVE-2006-6866 json | STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote ... | Not Provided | 2006-12-31 | 2026-04-23 |