phpkobo CVE Vulnerabilities & Metrics

Focus on phpkobo vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About phpkobo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with phpkobo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total phpkobo CVEs: 10
Earliest CVE date: 23 Mar 2010, 17:30 UTC
Latest CVE date: 30 Sep 2023, 15:15 UTC

Latest CVE reference: CVE-2023-5313

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical phpkobo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.09

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 8
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS phpkobo CVEs

These are the five CVEs with the highest CVSS scores for phpkobo, sorted by severity first and recency.

All CVEs for phpkobo

CVE-2023-5313 phpkobo vulnerability CVSS: 5.0 30 Sep 2023, 15:15 UTC

A vulnerability classified as problematic was found in phpkobo Ajax Poll Script 3.18. Affected by this vulnerability is an unknown functionality of the file ajax-poll.php of the component Poll Handler. The manipulation leads to improper enforcement of a single, unique action. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240949 was assigned to this vulnerability.

CVE-2023-41450 phpkobo vulnerability CVSS: 0 28 Sep 2023, 03:15 UTC

An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

CVE-2023-41447 phpkobo vulnerability CVSS: 0 28 Sep 2023, 03:15 UTC

Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component.

CVE-2023-41446 phpkobo vulnerability CVSS: 0 28 Sep 2023, 03:15 UTC

Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.

CVE-2023-41453 phpkobo vulnerability CVSS: 0 27 Sep 2023, 23:15 UTC

Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component.

CVE-2023-41452 phpkobo vulnerability CVSS: 0 27 Sep 2023, 23:15 UTC

Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.

CVE-2023-41451 phpkobo vulnerability CVSS: 0 27 Sep 2023, 23:15 UTC

Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.

CVE-2023-41449 phpkobo vulnerability CVSS: 0 27 Sep 2023, 23:15 UTC

An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

CVE-2023-41448 phpkobo vulnerability CVSS: 0 27 Sep 2023, 23:15 UTC

Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component.

CVE-2023-41445 phpkobo vulnerability CVSS: 0 27 Sep 2023, 23:15 UTC

Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component.

CVE-2010-1063 phpkobo vulnerability CVSS: 6.8 23 Mar 2010, 17:30 UTC

Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) codelib/cfg/common.inc.php, (2) form/app/common.inc.php, and (3) staff/app/common.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2010-1062 phpkobo vulnerability CVSS: 6.8 23 Mar 2010, 17:30 UTC

Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of these details are obtained from third party information.

CVE-2010-1061 phpkobo vulnerability CVSS: 6.8 23 Mar 2010, 17:30 UTC

Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) url/app/common.inc.php and (2) codelib/cfg/common.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2010-1060 phpkobo vulnerability CVSS: 6.8 23 Mar 2010, 17:30 UTC

Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.

CVE-2010-1059 phpkobo vulnerability CVSS: 6.8 23 Mar 2010, 17:30 UTC

Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2010-1058 phpkobo vulnerability CVSS: 6.8 23 Mar 2010, 17:30 UTC

Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.

CVE-2010-1057 phpkobo vulnerability CVSS: 6.8 23 Mar 2010, 17:30 UTC

Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a ..// (dot dot slash slash) in the LANG_CODE parameter to common.inc.php in (1) codelib/cfg/, (2) codelib/sys/, (3) staff/, and (4) staff/app/; and (5) staff/file.php. NOTE: some of these details are obtained from third party information.