Episodex develops a focused web-based guestbook product where the disclosed vulnerabilities center on access-control weaknesses, specifically forced-browsing conditions that permit unauthorized direct access to functionality. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Episodex over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1685HIGH episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp. | May 20, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1684MEDIUM Cross-site scripting (XSS) vulnerability in default.asp for episodex guestbook allows remote attackers to inject arbitrary web script or HTML via the Name field and other fields. | May 20, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Episodex.
Media articles that mention a CVE ID that affects a product developed by Episodex — matched by CVE ID, not by vendor name.