VendorsPHPSUGARphp_melodyall versions
Vulnerabilities

PHPSUGAR PHP Melody

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2017-15081
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
Published 2017-10-24 · Modified
9.81 PoCEPSS 0.024
CVE-2018-5211
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
Published 2018-01-09 · Modified
9.81 PoCEPSS 0.019
CVE-2017-15579
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
Published 2017-10-18 · Modified
9.81 PoCEPSS 0.015
CVE-2017-15578
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
Published 2017-10-18 · Modified
8.81 PoCEPSS 0.013
CVE-2021-47915
PHP Melody 3.0 SQL Injection Vulnerability via Edit Video Parameter
Published 2026-02-01 · Analyzed
8.8EPSS 0.006
CVE-2021-47914
PHP Melody 3.0 Persistent XSS Vulnerability via Edit Video Parameter
Published 2026-02-01 · Analyzed
6.4EPSS 0.003
CVE-2021-47912
PHP Melody 3.0 Non-Persistent Cross-Site Scripting via Multiple Parameters
Published 2026-02-01 · Analyzed
6.4EPSS 0.002
CVE-2021-47913
PHP Melody 3.0 Persistent Cross-Site Scripting via Video Editor
Published 2026-02-01 · Analyzed
6.4EPSS 0.002
CVE-2017-15648
In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter.
Published 2017-10-19 · Modified
6.1EPSS 0.007