Product
nexusphp project nexusphp
31 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-46890
CVE-2022-46889
CVE-2022-46888
CVE-2022-46887
CVE-2020-24771
CVE-2020-24770
CVE-2020-24769
CVE-2017-15305
CVE-2017-12792
CVE-2017-14534
CVE-2017-14512
CVE-2017-14347
CVE-2017-12906
CVE-2017-12838
CVE-2017-14076
CVE-2017-14070
CVE-2017-14069
CVE-2017-13669
CVE-2017-12679
CVE-2017-12981
CVE-2017-12776
CVE-2017-12680
CVE-2017-12910
CVE-2017-12909
CVE-2017-12908
CVE-2017-12907
CVE-2017-12798
CVE-2017-12777
CVE-2017-12655
CVE-2017-11651
CVE-2011-4026
< 1.7.33
Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by
< 1.7.33
A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanent
< 1.7.33
Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrar
< 1.7.33
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the
all versions
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
all versions
SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id p
all versions
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the c
all versions
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of
all versions
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
all versions
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulner
all versions
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.
all versions
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via
all versions
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for
all versions
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.
all versions
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.
all versions
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.
all versions
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
all versions
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
all versions
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.
all versions
SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delre
all versions
Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php.
all versions
SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or p
all versions
SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the useri
all versions
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the c
all versions
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.
all versions
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.
all versions
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.
all versions
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.
all versions
NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag.
all versions
SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id par