Basic B2B Script Project maintains a single web application product whose vulnerability profile centers on common application-layer input-handling and session-management weaknesses, including cross-site scripting, SQL injection, cross-site request forgery, and path-traversal flaws. These are durable, recurring issues in web application design; treat this as a compact vendor profile while live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Basic B2b Script Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17600CRITICAL Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. | Dec 13, 2017 | 9.8 | 42 | NO | YES |
CVE-2018-20644HIGH PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature. | Mar 21, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-20646MEDIUM PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory. | Mar 21, 2019 | 6.5 | 21 | NO | NO |
CVE-2018-20645MEDIUM PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field. | Mar 21, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Basic B2b Script Project.
Media articles that mention a CVE ID that affects a product developed by Basic B2b Script Project — matched by CVE ID, not by vendor name.