Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aspindir

First CVE: Sep 21, 2006Active for: 20 yearsTotal CVEs: 41
44.3
VTI Score
High

Aspindir's vulnerability portfolio centers on a collection of web-facing applications and e-commerce platforms including Angelo Emlak, Shibby Shop, XWeblog, and Alişveriş Sitesi Script, which occupy a modest but specialized niche in the vulnerability landscape. The vendor's disclosures cluster heavily around application-layer input-handling flaws, particularly SQL injection and cross-site scripting vulnerabilities, reflecting the common weaknesses found in custom web applications and content-management systems. Notably, vulnerabilities from this vendor have a strong tendency to acquire public exploit code and tooling, making them targets for opportunistic exploitation once details emerge. Defenders operating these platforms should prioritize patching advisories and restrict direct internet exposure where feasible; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Aspindir over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2006
19 years ago
Most Recent CVE
Oct 5, 2011
5,406 days ago

Products(24 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4144HIGH
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter.
Nov 2, 20107.532NOYES
CVE-2008-3888HIGH
SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a member_details action.
Sep 2, 20087.532NOYES
CVE-2010-4856HIGH
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.
Oct 5, 20117.531NOYES
CVE-2010-4855HIGH
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter.
Oct 5, 20117.531NOYES
CVE-2007-3884HIGH
SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later rep
Jul 18, 20077.530NOYES
CVE-2008-2882HIGH
upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unspecified other impact via a dir
Jun 26, 20087.529NOYES
CVE-2008-6640HIGH
Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) uyeadmin.asp and (2) profil.asp. NOTE:
Apr 7, 20097.528NOYES
CVE-2009-0447HIGH
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the user parameter (aka UserName field)
Feb 10, 20097.528NOYES
CVE-2008-5707HIGH
SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the catno parameter.
Dec 24, 20087.528NOYES
CVE-2008-5057HIGH
SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the film parameter. NOTE: the provenance of this
Nov 13, 20087.528NOYES
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
39%
61%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown41 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown41 (100.0%)
User Interaction
None0 (0.0%)
Unknown41 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown41 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
34 CVEs
82.9% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aspindir.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aspindir — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aspindir's Products

View all 1 CNAs →

Top CWEs