Bitmixsoft's vulnerability footprint is confined to a small set of PHP-based web applications, including the PHP-Jokesite and PHP-Lance projects, with the observed weakness classes centered on input-handling and database-access issues. The recurrent vulnerabilities reflect path traversal and SQL injection flaws endemic to web application parsing and query construction, highlighting the importance of input validation in this product tier. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bitmixsoft over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2457HIGH SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | May 27, 2008 | 7.5 | 28 | NO | YES |
CVE-2009-2923MEDIUM Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.ph | Aug 21, 2009 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bitmixsoft.
Media articles that mention a CVE ID that affects a product developed by Bitmixsoft — matched by CVE ID, not by vendor name.