CVE Tools

EXV2

11 CVEs tracked since 2006. Since Sep 2006, none of them reached CISA KEV.

EXV2 CVEs per month

Sep 2006 to Nov 2010. Point at a month, or focus the strip and use the arrow keys.
EXV2 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2006-0910
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-0220
2007-03null or fewer
2007-0420
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-0810
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-0340
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-1110

Products

The products that kept showing up in EXV2's monthly top three, with their CVEs summed over those months.

  1. Content Management System64 months
  2. EXV252 months
  3. Bamagalerie11 month

Latest CVEs

The 11 most recently published vulnerabilities affecting EXV2.

  1. CVE-2010-4155Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and...4.3
  2. CVE-2008-1406SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.6.8
  3. CVE-2008-1404SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the kid parameter.6.8
  4. CVE-2008-1407SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.6.8
  5. CVE-2008-1349SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.7.5
  6. CVE-2007-4365Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this ...4.3
  7. CVE-2007-1965Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) ...4.3
  8. CVE-2007-1966Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.9.1
  9. CVE-2006-7080Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.4.3
  10. CVE-2006-7079Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execu...9.8
  11. CVE-2006-5030SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.7.5

The record

Peak rank
#21 in Mar 2008
Busiest month shown
Mar 2008, 4 CVEs
Months with a KEV entry
0 since Sep 2006
Monthly snapshots
6 since 2006
EXV2's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store