Editeurscripts develops a portfolio of web-based content management and portal products, including FAQ, admin, contacts, news, and partner management systems, where vulnerabilities cluster around application-layer input-handling issues such as cross-site scripting and SQL injection. Despite the narrow product scope, the vendor's disclosures have frequently acquired public exploit code, reflecting the accessibility and appeal of web-application flaws to a broad attack base. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Editeurscripts over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6016HIGH SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3952. N | Jan 30, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6015HIGH Multiple SQL injection vulnerabilities in search.php in EsFaq 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) keywords and (2) cat parameters. NOTE: the p | Jan 30, 2009 | 7.5 | 19 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in EditeurScripts EsContacts 1.0 allow remote authenticated users to inject arbitrary web script or HTML via the msg parameter t | Apr 30, 2008 | 3.5 | 19 | NO | YES |
CVE-2008-6876MEDIUM Cross-site scripting (XSS) vulnerability in login.php in EsPartenaires 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the EsContac | Jul 24, 2009 | 4.3 | 16 | NO | NO |
CVE-2009-2581MEDIUM Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | Jul 23, 2009 | 4.3 | 15 | NO | NO |
CVE-2008-6868MEDIUM Cross-site scripting (XSS) vulnerability in default/login.php in EditeurScripts EsBaseAdmin 2.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter | Jul 23, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Editeurscripts.
Media articles that mention a CVE ID that affects a product developed by Editeurscripts — matched by CVE ID, not by vendor name.