CVE Tools

Postnuke-software-foundation

39 CVEs tracked since 2002. Since Feb 2002, none of them reached CISA KEV.

Postnuke-software-foundation CVEs per month

Feb 2002 to May 2008. Point at a month, or focus the strip and use the arrow keys.
Postnuke-software-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2002-0210
2002-03null or fewer
2002-04null or fewer
2002-05null or fewer
2002-0610
2002-0710
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-0320
2005-0440
2005-05110
2005-06null or fewer
2005-0730
2005-0820
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-0120
2006-0230
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-1220
2007-0130
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-1130
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-0510

Products

The products that kept showing up in Postnuke-software-foundation's monthly top three, with their CVEs summed over those months.

  1. Postnuke3612 months
  2. Postcalendar22 months
  3. Pnencyclopedia11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Postnuke-software-foundation.

  1. CVE-2008-2191SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a display_term action to in...6.8
  2. CVE-2008-2012SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action.7.5
  3. CVE-2003-1537Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.5.0
  4. CVE-2004-2751SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.6.8
  5. CVE-2004-2752Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle...4.3
  6. CVE-2007-3584SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execute arbitrary SQL commands via the order parameter.7.5
  7. CVE-2007-3052SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter.7.5
  8. CVE-2007-2492SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action.7.5
  9. CVE-2007-1158Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.5.0
  10. CVE-2007-0385The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.7.8
  11. CVE-2007-0386Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."10.0
  12. CVE-2007-0384Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.5.1
  13. CVE-2006-6267PostNuke 0.7.5.0, and certain minor versions, allows remote attackers to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message.7.8
  14. CVE-2006-6233SQL injection vulnerability in the Downloads module for unknown versions of PostNuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewdownloaddetails operati...7.5
  15. CVE-2006-5733Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cook...7.5

The record

Peak rank
#5 in May 2005
Busiest month shown
May 2005, 11 CVEs
Months with a KEV entry
0 since Feb 2002
Monthly snapshots
14 since 2002
Postnuke-software-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store