Dsmall Project maintains a narrowly scoped application whose vulnerability exposure centers on web-layer input handling and information disclosure, particularly cross-site scripting and improper exposure of sensitive data. Despite modest disclosure volume, the vendor's product occupies a more prominent position in certain security contexts than its niche footprint might initially suggest. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dsmall Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9014HIGH dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request. | Mar 25, 2018 | 7.5 | 22 | NO | NO |
CVE-2018-9016MEDIUM dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI. | Mar 25, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-9307MEDIUM dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html. | Apr 4, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-9015MEDIUM dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box). | Mar 25, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-8906MEDIUM dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/ | Mar 22, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-9017MEDIUM dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI. | Mar 25, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dsmall Project.
Media articles that mention a CVE ID that affects a product developed by Dsmall Project — matched by CVE ID, not by vendor name.