Fortunescripts develops a narrow set of web application clones, including learning-platform and e-commerce variants, that present application-layer attack surfaces. The observed vulnerability pattern centers on input-handling and request-validation weaknesses, including cross-site scripting, SQL injection, and cross-site request forgery, which are characteristic of web applications lacking mature input sanitization and anti-CSRF protections. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fortunescripts over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17573CRITICAL FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. | Dec 13, 2017 | 9.8 | 40 | NO | YES |
CVE-2017-17903HIGH FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel. | Dec 27, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-17904MEDIUM FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile. | Dec 27, 2017 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fortunescripts.
Media articles that mention a CVE ID that affects a product developed by Fortunescripts — matched by CVE ID, not by vendor name.