CVE Tools

Dynpg

4 CVEs tracked since 2010. Since Apr 2010, none of them reached CISA KEV.

Dynpg CVEs per month

Apr 2010 to Dec 2010. Point at a month, or focus the strip and use the arrow keys.
Dynpg CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2010-0410
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-1230

Products

The products that kept showing up in Dynpg's monthly top three, with their CVEs summed over those months.

  1. Dynpg42 months

Latest CVEs

The 11 most recently published vulnerabilities affecting Dynpg.

  1. CVE-2020-27406Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.5.4
  2. CVE-2021-27526A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.4.8
  3. CVE-2021-27527A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.4.8
  4. CVE-2021-27530A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php.4.8
  5. CVE-2021-27528A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.4.8
  6. CVE-2021-27531A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter.4.8
  7. CVE-2021-27529A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.4.8
  8. CVE-2010-4400SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_UserId parameter.7.5
  9. CVE-2010-4401languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.5.0
  10. CVE-2010-4399Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the CHG...4.3
  11. CVE-2010-1299Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arb...5.1

The record

Peak rank
#31 in Dec 2010
Busiest month shown
Dec 2010, 3 CVEs
Months with a KEV entry
0 since Apr 2010
Monthly snapshots
2 since 2010
Dynpg's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store