Codewidgets develops a narrowly scoped portfolio of web-based business applications including event registration, payroll and timekeeping, and real estate listing templates. The vendor's disclosures center on SQL injection and related input-validation weaknesses characteristic of web application platforms, and frequently attract public exploit code; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codewidgets over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4109HIGH SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | Jul 31, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-4110HIGH SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Pass | Jul 31, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-4106MEDIUM SQL injection vulnerability in login.asp in CodeWidgets Pay Roll - Time Sheet and Punch Card Application With Web Interface allows remote attackers to execute arbitrary SQL command | Jul 31, 2007 | 6.8 | 26 | NO | YES |
CVE-2007-4111MEDIUM SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrar | Jul 31, 2007 | 6.8 | 26 | NO | YES |
CVE-2007-5704HIGH Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and | Oct 29, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-4108HIGH SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | Jul 31, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codewidgets.
Media articles that mention a CVE ID that affects a product developed by Codewidgets — matched by CVE ID, not by vendor name.