CVE-2017-15970: Phpcityportal

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.

Affected products

Published 2017-10-29. Last modified 2026-06-17.