VYPR
Vendor

Opensource Socialnetwork

Products
3
CVEs
20
Across products
20
Status
Private

Products

3

Recent CVEs

20
  • CVE-2023-6418CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via videos.php in the id parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6417CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via update.php in the id parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6416CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signup2.php in the emailadd parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the…

  • CVE-2023-6415CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signin.php in the user parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6414CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via perfil.php in the id and user parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to…

  • CVE-2023-6413CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photos.php in the id and user parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to…

  • CVE-2023-6412CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photo.php in multiple parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6411CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via home.php in the update parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6410CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via editprofile.php in multiple parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the…

  • CVE-2025-63441HigNov 3, 2025
    risk 0.47cvss 7.3epss 0.00

    Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.

  • CVE-2026-41309HigApr 24, 2026
    risk 0.46cvss 8.2epss 0.00

    Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While…

  • CVE-2025-63585MedNov 5, 2025
    risk 0.42cvss 6.5epss 0.00

    OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.

  • CVE-2023-6420MedNov 30, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via signup2.php in the emailadd parameter, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the…

  • CVE-2023-6419MedNov 30, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script version 1.0 that allows a XSS via editprofile.php in multiple parameters, the exploitation of which could allow a remote attacker to send a specially crafted JavaScript payload and partially take over the…

  • CVE-2022-34966HigJul 25, 2022
    risk 0.42cvss 7.5epss 0.01

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.

  • CVE-2022-34965HigJul 25, 2022
    risk 0.40cvss 7.2epss 0.02

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project…

  • CVE-2020-10560MedMar 30, 2020
    risk 0.39cvss 5.9epss 0.04

    An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force…

  • CVE-2022-34962MedJul 25, 2022
    risk 0.28cvss 5.4epss 0.01

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.

  • CVE-2022-34963MedJul 25, 2022
    risk 0.28cvss 5.4epss 0.01

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.

  • CVE-2022-34961MedJul 25, 2022
    risk 0.28cvss 5.4epss 0.01

    OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module.