Deltascripts' vulnerability footprint centers on a portfolio of PHP-based web applications including classifieds, link management, publishing, and documentation platforms. The vendor's disclosures consistently reflect input-handling weaknesses endemic to server-side web applications: SQL injection, code injection, and cross-site scripting recur across its product line, representing common attack vectors against PHP codebases. Public exploit code has frequently been developed for Deltascripts vulnerabilities, underscoring the appeal of these widely deployed web frameworks to automated attack tooling. Defenders should treat Deltascripts product updates as priority within web-application portfolios and maintain layered input validation and output encoding controls; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deltascripts over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0566MEDIUM PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full | Feb 5, 2008 | 6.8 | 38 | NO | YES |
CVE-2010-4914HIGH PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_pa | Oct 8, 2011 | 7.5 | 31 | NO | YES |
CVE-2008-6720HIGH SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parame | Apr 13, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5806HIGH SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter | Dec 31, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5805HIGH SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a diff | Dec 31, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5648HIGH SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary SQL commands via the admin_username parameter. NOTE: some | Dec 17, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-5828HIGH SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | Nov 10, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-5208HIGH Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the | Oct 10, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-3329HIGH SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter. | Jun 30, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-0719HIGH SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which | Feb 15, 2006 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deltascripts.
Media articles that mention a CVE ID that affects a product developed by Deltascripts — matched by CVE ID, not by vendor name.