Boxug maintains the Trape web application, a modestly represented product in the vulnerability landscape with a focused exposure profile centered on input-handling defects. The recurring weakness classes—cross-site scripting and SQL injection—reflect common application-layer validation gaps that defenders should address through input sanitization and parameterized queries; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boxug over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17713CRITICAL Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register cou | Dec 16, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-17714MEDIUM Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode p | Dec 16, 2017 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boxug.
Media articles that mention a CVE ID that affects a product developed by Boxug — matched by CVE ID, not by vendor name.