Application Dynamics has a narrow vulnerability footprint centered on its CartWeaver e-commerce platform for ColdFusion environments, with observed disclosures clustering around SQL injection and input-handling defects. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Application Dynamics over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2918HIGH SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a rel | Jun 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-2046MEDIUM Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) catego | Apr 26, 2006 | 6.4 | 27 | NO | YES |
CVE-2006-2047MEDIUM Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allows remote attackers to obtain sensitive information via an invalid (1) secondary, (2) PageNum_Results, (3) catego | Apr 26, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Application Dynamics.
Media articles that mention a CVE ID that affects a product developed by Application Dynamics — matched by CVE ID, not by vendor name.