Codetoad develops a narrow line of web-application products focused on ASP-based forum and e-commerce solutions, where its vulnerability disclosures have centered on application-layer input-handling issues including cross-site scripting and SQL injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codetoad over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6890HIGH SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL commands via the message_id parameter. | Aug 3, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6891MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_mess | Aug 3, 2009 | 4.3 | 21 | NO | YES |
CVE-2008-6500MEDIUM Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI | Mar 20, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codetoad.
Media articles that mention a CVE ID that affects a product developed by Codetoad — matched by CVE ID, not by vendor name.