Derbynet operates a modest, niche derby-racing event-management platform that concentrates vulnerability exposure around a single application product. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through a consistent pattern of web-application input-handling weaknesses—including cross-site scripting, SQL injection, code injection, path traversal, and related output-encoding flaws—that reflect parser and validation gaps endemic to user-facing web applications. Defenders managing Derbynet deployments should prioritize patching and treat this vendor's advisories as high-impact; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Derbynet over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31818CRITICAL Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component. | Apr 12, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-30923CRITICAL SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering | Apr 18, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-30922CRITICAL SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering. | Apr 18, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-30929HIGH Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php | Apr 18, 2024 | 8.0 | 23 | NO | NO |
CVE-2024-30928HIGH SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/query.slide.next.inc | Apr 18, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-30920HIGH Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component. | Apr 18, 2024 | 7.4 | 22 | NO | NO |
CVE-2024-30925MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component. | Apr 18, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-30921MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php component. | Apr 18, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-30927MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component. | Apr 18, 2024 | 6.3 | 17 | NO | NO |
CVE-2024-30926MEDIUM Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component. | Apr 18, 2024 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Derbynet.
Media articles that mention a CVE ID that affects a product developed by Derbynet — matched by CVE ID, not by vendor name.