Belchior Foundry develops a narrow product line centered on vCard utilities and related contact-management tools that serve specialized use cases in data handling and interchange. The vendor's vulnerability profile is characterized by a notable tendency toward public exploit availability, reflecting the inherent exploitability of the input-handling and web-generation issues that recur across its products, particularly cross-site scripting weaknesses in vCard parsing and rendering contexts. Defenders should treat exploit availability as a signal for prioritization rather than a measure of active deployment risk; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Belchior Foundry over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3474HIGH Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to (a) gbrowse.php, (2) c | Jul 10, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-4769HIGH SQL injection vulnerability in addrbook.php in Belchior Foundry vCard PRO 3.1 allows remote attackers to execute arbitrary SQL commands via the addr_id parameter. NOTE: the proven | Dec 31, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-3332HIGH PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter. | Oct 27, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-0054MEDIUM Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject arbitrary web script or HTML via the sortby parameter. | Jan 4, 2007 | 6.8 | 26 | NO | YES |
CVE-2004-1828MEDIUM Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a di | Dec 31, 2004 | 5.0 | 23 | NO | YES |
CVE-2006-1230MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) | Mar 14, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-2810MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Belchior Foundry vCard 2.9 allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) toprat | Jun 5, 2006 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Belchior Foundry.
Media articles that mention a CVE ID that affects a product developed by Belchior Foundry — matched by CVE ID, not by vendor name.