Almondsoft's vulnerability footprint clusters around a narrow line of classifieds and personals web applications, with the durable signal centered on application-layer input-handling defects including cross-site scripting and SQL injection. The vendor's disclosures frequently acquire public exploit code, reflecting the web-application nature of its products and their exposure to automated scanning and tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Almondsoft over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3226HIGH SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL c | Sep 16, 2009 | 7.5 | 29 | NO | YES |
CVE-2009-3154HIGH SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in | Sep 10, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2567HIGH SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to in | Jul 22, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-3225MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to injec | Sep 16, 2009 | 4.3 | 22 | NO | YES |
CVE-2009-3155MEDIUM Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTM | Sep 10, 2009 | 4.3 | 21 | NO | YES |
CVE-2005-4312HIGH SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 17, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-4313HIGH SQL injection vulnerability in index.php in AlmondSoft Almond Personals 4.05 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 17, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-3741HIGH Almond Classifieds does not properly verify the password, which allows attackers to bypass access restrictions. | Nov 22, 2005 | 7.5 | 19 | NO | NO |
CVE-2009-3227MEDIUM Cross-site scripting (XSS) vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to inject arb | Sep 16, 2009 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Almondsoft.
Media articles that mention a CVE ID that affects a product developed by Almondsoft — matched by CVE ID, not by vendor name.