Vulnerabilities > Phpvibe

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-39171 Path Traversal vulnerability in PHPvibe
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
network
low complexity
phpvibe CWE-22
critical
9.8
2024-06-18 CVE-2024-6083 Unrestricted Upload of File with Dangerous Type vulnerability in PHPvibe 11.0.46
A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46.
network
low complexity
phpvibe CWE-434
critical
9.8
2024-06-17 CVE-2024-6082 Cross-site Scripting vulnerability in PHPvibe 11.0.46
A vulnerability, which was classified as problematic, has been found in PHPVibe 11.0.46.
network
low complexity
phpvibe CWE-79
6.1
2016-08-26 CVE-2015-5399 Cross-site Scripting vulnerability in PHPvibe 4.20
Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.
network
low complexity
phpvibe CWE-79
5.4