Nexusphp Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 16
    Known Exploited: 0
    5
    Critical Level Threats
    1
    High Level Threats
    10
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2017-15305

    XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.

    Last Modified: Apr 20, 2025
    Published: Oct 15, 2017

    CVE-2017-12792

    Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php.

    Last Modified: Apr 20, 2025
    Published: Oct 02, 2017

    CVE-2017-14534

    Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.

    Last Modified: Apr 20, 2025
    Published: Sep 18, 2017

    CVE-2017-14512

    NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.

    Last Modified: Apr 20, 2025
    Published: Sep 17, 2017

    CVE-2017-14347

    NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.

    Last Modified: Apr 20, 2025
    Published: Sep 12, 2017
    Items Per Page