1 Script maintains a narrow vulnerability footprint centered on a pair of closely related products—1 Book and 1 Search—that serve specialized publishing and search functionality. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 1 Script over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2638HIGH Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, w | Jun 10, 2008 | 10.0 | 36 | NO | YES |
CVE-2005-4091MEDIUM Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script 1-Search 1.8 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | Dec 8, 2005 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 1 Script.
Media articles that mention a CVE ID that affects a product developed by 1 Script — matched by CVE ID, not by vendor name.