Lifetype

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 10
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2011-3751

    LifeType 1.2.10 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/badbehavior/pluginbadbehavior.class.php.

    Last Modified: Apr 11, 2025
    Published: Sep 23, 2011

    CVE-2008-2629

    SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php.

    Last Modified: Apr 23, 2026
    Published: Jun 10, 2008

    CVE-2008-2196

    Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the newBlogUserName parameter in an addBlogUser action, a different vector than CVE-2008-2178.

    Last Modified: Apr 23, 2026
    Published: May 14, 2008

    CVE-2008-2178

    Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the searchTerms parameter in an editArticleCategories operation (aka an admin category search).

    Last Modified: Apr 23, 2026
    Published: May 13, 2008

    CVE-2007-0979

    Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents) via a "crafted URL."

    Last Modified: Apr 23, 2026
    Published: Feb 16, 2007
    Items Per Page
    Lifetype Vulnerabilities & Security CVEs | CVE-DB