CVE-2017-6089: Phpcollab

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to calendar/deletecalendar.php.

Affected products

  • Phpcollab Phpcollab: up to and including 2.5.1

Published 2017-10-03. Last modified 2026-06-17.