Phenotype-cms
Phenotype-cms Phenotype CMS: vulnerabilities and CVEs
Phenotype-cms Phenotype CMS has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-0407 | High (7.5) | 1.1% | — | Jan 11, 2011 | SQL injection vulnerability in the store function in _phenotype/system/class/PhenoTypeDataObject.class.php in Phenotype CMS 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URI, as… |
| CVE-2009-3543 | High (7.5) | 2.0% | — | Oct 2, 2009 | SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name). |
| CVE-2009-2951 | High (7.5) | 0.62% | — | Aug 24, 2009 | Phenotype CMS before 2.9 does not use a random salt value for password encryption, which makes it easier for context-dependent attackers to determine cleartext passwords. |