← Back

Phpee

phpee

4 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Pphlogger
pphlogger
Ya Book
ya_book
Power Phlogger
power_phlogger

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpee
1Pphlogger
Apr 23, 2026
Dec 10, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.php, (5) head_stuff.inc.php, (6) loglist.in...Show more
PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.php, (5) head_stuff.inc.php, (6) loglist.inc.php, and (7) pphlogger_send.inc.php in include/, which reveals the installation path in an error message.Show less
1Phpee
1Pphlogger
Apr 23, 2026
Dec 10, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the edit parameter.
1Phpee
1Power Phlogger
Apr 23, 2026
Jun 26, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.php.
1Phpee
1Ya Book
Apr 23, 2026
Apr 25, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php.