← Back

Phenotype Cms

phenotype-cms

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Phenotype Cms
phenotype_cms

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phenotype Cms
1Phenotype Cms
Apr 29, 2026
Jan 11, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the store function in _phenotype/system/class/PhenoTypeDataObject.class.php in Phenotype CMS 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URI, as demonstrated...Show more
SQL injection vulnerability in the store function in _phenotype/system/class/PhenoTypeDataObject.class.php in Phenotype CMS 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URI, as demonstrated by Gallery/gal_id/1/image1,1.html. NOTE: some of these details are obtained from third party information.Show less
1Phenotype Cms
1Phenotype Cms
Apr 23, 2026
Oct 2, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name).
1Phenotype Cms
1Phenotype Cms
Apr 23, 2026
Aug 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Phenotype CMS before 2.9 does not use a random salt value for password encryption, which makes it easier for context-dependent attackers to determine cleartext passwords.