Products: 13
    Vulnerabilities: 40
    Known Exploited: 0
    2
    Critical Level Threats
    25
    High Level Threats
    13
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-30177

    There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to be two letters, and the OrderBy field is not validated to be one of LASTNAME, CITY, or STATE.

    Last Modified: Nov 21, 2024
    Published: Apr 07, 2021

    CVE-2014-3934

    SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] parameter to modules.php.

    Last Modified: Apr 12, 2025
    Published: Jun 02, 2014

    CVE-2010-5083

    SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.

    Last Modified: Apr 11, 2025
    Published: Feb 14, 2012

    CVE-2011-3784

    Francisco Burzi PHP-Nuke 8.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Odyssey/theme.php and certain other files.

    Last Modified: Apr 11, 2025
    Published: Sep 24, 2011

    CVE-2011-1480

    SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via the chng_uid parameter.

    Last Modified: Apr 11, 2025
    Published: Jun 21, 2011
    Items Per Page