Phpsugar
Phpsugar PHP Melody: vulnerabilidades y CVE
Phpsugar PHP Melody tiene 9 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses4
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-47915 | Alta (8.6) | 0.59% | — | 1 feb 2026 | PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated 'vid' parameter… |
| CVE-2021-47914 | Media (5.1) | 0.35% | — | 1 feb 2026 | PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this… |
| CVE-2021-47913 | Media (5.1) | 0.26% | — | 1 feb 2026 | PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent… |
| CVE-2021-47912 | Media (5.1) | 0.26% | — | 1 feb 2026 | PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute… |
| CVE-2018-5211 | Crítica (9.8) | 1.9% | — | 9 ene 2018 | PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. |
| CVE-2017-15081 | Crítica (9.8) | 2.4% | — | 24 oct 2017 | In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. |
| CVE-2017-15648 | Media (6.1) | 0.66% | — | 19 oct 2017 | In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter. |
| CVE-2017-15579 | Crítica (9.8) | 1.5% | — | 18 oct 2017 | In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php. |
| CVE-2017-15578 | Alta (8.8) | 1.3% | — | 18 oct 2017 | In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.