Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aj Square

First CVE: Mar 7, 2007Active for: 19 yearsTotal CVEs: 32
54.9
VTI Score
TOP TARGET

Aj Square develops a portfolio of web-based marketplace and content-management applications including auction, HYIP investment, article, and classified-listing platforms. The vendor's disclosures center on application-layer input-handling and authentication weaknesses—SQL injection, cross-site scripting, and improper authentication—that are characteristic of database-driven web applications and tend to acquire public exploit tooling. Current severity, in-the-wild exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 94% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Aj Square over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2007
19 years ago
Most Recent CVE
Mar 11, 2015
4,153 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-1876HIGH
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding actio
May 12, 20107.532NOYES
CVE-2010-2916HIGH
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter.
Jul 30, 20107.531NOYES
CVE-2008-2532HIGH
SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter.
Jun 3, 20087.531NOYES
CVE-2010-2915HIGH
SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.
Jul 30, 20107.529NOYES
CVE-2008-7051HIGH
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesusp
Aug 24, 20097.529NOYES
CVE-2008-7041HIGH
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
Aug 24, 20097.529NOYES
CVE-2008-6965HIGH
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote att
Aug 13, 20097.529NOYES
CVE-2009-3203HIGH
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.
Sep 16, 20097.528NOYES
CVE-2008-7044HIGH
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via th
Aug 24, 20097.528NOYES
CVE-2009-2779HIGH
SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action.
Aug 17, 20097.528NOYES
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
25%
75%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown32 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown32 (100.0%)
User Interaction
None0 (0.0%)
Unknown32 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown32 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
32 CVEs
100.0% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aj Square.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aj Square — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aj Square's Products

View all 1 CNAs →

Top CWEs