2bits produces a narrowly scoped set of web-based modules and plugins—notably its Currency and UserPoints components—that extend e-commerce and community platforms. The recurrent vulnerability signal across these products centers on web-layer input and state-management weaknesses: cross-site request forgery, cross-site scripting, and exposure of sensitive information, which are characteristic of application-level integration points. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 2bits over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10930MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects Currency: from 0.0.0 before 3.5.0. | Oct 30, 2025 | 4.3 | 17 | NO | NO |
CVE-2010-1074MEDIUM Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified ve | Mar 23, 2010 | 4.3 | 14 | NO | NO |
Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data | Oct 26, 2009 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 2bits.
Media articles that mention a CVE ID that affects a product developed by 2bits — matched by CVE ID, not by vendor name.