Fobybus maintains a social-media platform codebase where the observed vulnerability surface centers on web-application input handling and session management, with recurring issues in cross-site request forgery, cross-site scripting, SQL injection, session expiration, and credential protection. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fobybus over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40174CRITICAL Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Insufficient session expiration is a web application secur | Aug 18, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-39344HIGH social-media-skeleton is an uncompleted social media project. A SQL injection vulnerability in the project allows UNION based injections, which indirectly leads to remote code exec | Aug 4, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-40172HIGH Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forgery (CSRF) attack is a type of ma | Aug 18, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-40173HIGH Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Social media skeleton did not prope | Aug 18, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-39518MEDIUM social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting | Aug 8, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fobybus.
Media articles that mention a CVE ID that affects a product developed by Fobybus — matched by CVE ID, not by vendor name.