Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Php Melody HIGH 8.8
CVE-2021-47915

PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious…

No fix yet
Fix from $1,950 2026-02-01
Php Melody MEDIUM 5.4
CVE-2021-47912

PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers …

No fix yet
Fix from $1,600 2026-02-01
Php Melody MEDIUM 5.4
CVE-2021-47913

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts.…

No fix yet
Fix from $1,600 2026-02-01
Php Melody MEDIUM 5.4
CVE-2021-47914

PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attacker…

No fix yet
Fix from $1,600 2026-02-01
Php Melody CRITICAL 9.8
CVE-2018-5211

PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.

No fix yet
Fix from $2,300 2018-01-09
Php Melody CRITICAL 9.8
CVE-2017-15081

In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.

No fix yet
Fix from $2,300 2017-10-24
Php Melody MEDIUM 6.1
CVE-2017-15648

In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter.

Fix: after 2.7.2
Fix from $1,600 2017-10-19
Php Melody CRITICAL 9.8
CVE-2017-15579

In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.

Fix: after 2.7.2
Fix from $2,300 2017-10-18
Php Melody HIGH 8.8
CVE-2017-15578

In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.

Fix: after 2.7.2
Fix from $1,950 2017-10-18
Ultimate Regnow Affiliate HIGH 7.5
CVE-2009-2895

SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat p…

No fix yet
Fix from $1,950 2009-08-20