Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Alstrasoft

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 56
41.8
VTI Score
High

Alstrasoft's vulnerability footprint spans a modest but well-represented collection of web-based and hosting-related products, including affiliate network, video sharing, web directory, and social collaboration platforms. The vendor's disclosures concentrate on application-layer input-handling weaknesses, dominated by SQL injection and cross-site scripting vulnerabilities that are characteristic of server-side web applications, alongside a broad category of other structural flaws. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the relative accessibility of web application attack surfaces and the appeal of such vulnerabilities to security researchers and tool developers. Defenders should prioritize input-validation hardening and parameterized queries across this vendor's products; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
56
Total CVEs
More Total CVEs than 99% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Alstrasoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Aug 11, 2009
6,191 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (56 CVEs).

56 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-2776HIGH
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to
May 21, 200710.038NOYES
CVE-2007-2824HIGH
SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal acti
May 22, 200710.036NOYES
CVE-2007-2775HIGH
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrati
May 21, 200710.036NOYES
CVE-2008-5649HIGH
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the username parameter.
Dec 17, 200810.035NOYES
CVE-2006-4913HIGH
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary c
Sep 21, 20067.532NOYES
CVE-2007-2017HIGH
siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.
Apr 12, 20077.531NONO
CVE-2008-6932HIGH
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a file with an executable extensio
Aug 11, 20097.530NOYES
CVE-2007-4085MEDIUM
Multiple SQL injection vulnerabilities in AlstraSoft AskMe Pro allow remote attackers to execute arbitrary SQL commands via the (1) que_id parameter to forum_answer.php or (2) the
Jul 30, 20076.830NOYES
CVE-2007-2777HIGH
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an ar
May 21, 20077.530NOYES
CVE-2005-3797HIGH
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath]
Nov 24, 20057.529NOYES
View all 56 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products56 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown56 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown56 (100.0%)
User Interaction
None0 (0.0%)
Unknown56 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown56 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (56 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
51.8% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Alstrasoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Alstrasoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Alstrasoft's Products

View all 1 CNAs →

Top CWEs