Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Advanced Real Estate Script Project

First CVE: Dec 13, 2017Active for: 9 yearsTotal CVEs: 13
30.8
VTI Score
Low

Advanced Real Estate Script Project's vulnerability profile concentrates in its real-estate web application product and reflects the characteristic input-handling and access-control weaknesses of server-side web software: cross-site scripting, SQL injection, CSRF, and memory-safety issues recur across disclosures. A meaningful share of the vulnerabilities reach serious severity, and public exploit code has emerged for some flaws, underscoring the need for defenders deploying this software to prioritize patching and input-validation hardening. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Advanced Real Estate Script Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2017
8 years ago
Most Recent CVE
Jan 5, 2020
2,393 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-17603CRITICAL
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
Dec 13, 20179.842NOYES
CVE-2018-15187HIGH
PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.
Aug 10, 20188.025NONO
CVE-2019-20337HIGH
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection.
Jan 5, 20207.223NONO
CVE-2018-15188MEDIUM
PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a pro
Aug 10, 20186.522NONO
CVE-2019-20336MEDIUM
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.
Jan 5, 20206.121NONO
CVE-2018-5073MEDIUM
Online Ticket Booking has CSRF via admin/movieedit.php.
Jan 3, 20186.821NONO
CVE-2018-15189MEDIUM
PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.
Aug 10, 20185.420NONO
CVE-2018-5072MEDIUM
Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter.
Jan 3, 20184.818NONO
CVE-2018-5078MEDIUM
Online Ticket Booking has XSS via the admin/eventlist.php cast parameter.
Jan 3, 20184.817NONO
CVE-2018-5077MEDIUM
Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter.
Jan 3, 20184.817NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
77%
15%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (23.1%)
Unknown0 (0.0%)
Required10 (76.9%)
Privileges Required
Low3 (23.1%)
High8 (61.5%)
None2 (15.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Advanced Real Estate Script Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Advanced Real Estate Script Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Advanced Real Estate Script Project's Products

View all 1 CNAs →

Top CWEs