PhpsugarCVEs & Vulnerabilities

10 CVEs affecting Phpsugar products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

php melody 9ultimate regnow affiliate 1
CVE-2021-47915HIGH

PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated 'vid' parameter to execute arbitrary database queries and potentially compromise the web application and database management system.

1 Feb 2026
8.8
CVSS
CVE-2021-47914MEDIUM

PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading to session hijacking, persistent phishing, and manipulation of application modules.

1 Feb 2026
5.4
CVSS
CVE-2021-47913MEDIUM

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.

1 Feb 2026
5.4
CVSS
CVE-2021-47912MEDIUM

PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute client-side attacks and potentially hijack user sessions.

1 Feb 2026
5.4
CVSS
CVE-2018-5211CRITICALpoc

PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.

9 Jan 2018
9.8
CVSS
CVE-2017-15081CRITICALpoc

In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.

24 Oct 2017
9.8
CVSS
CVE-2017-15648MEDIUM

In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter.

20 Oct 2017
6.1
CVSS
CVE-2017-15579CRITICALpoc

In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.

18 Oct 2017
9.8
CVSS
CVE-2017-15578HIGHpoc

In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.

18 Oct 2017
8.8
CVSS
CVE-2009-2895HIGHpoc

SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

20 Aug 2009
7.5
CVSS
← PrevPage 1 / 1Next →