The Groupon Clone Script Project centers on a web application template intended for building marketplace-style e-commerce platforms, and its vulnerability profile reflects characteristic issues in this application category. The recurring weakness classes—cross-site scripting and SQL injection—signal deficiencies in input handling and parameterized query construction that are endemic to web application frameworks. Current exposure counts and live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Groupon Clone Script Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17638CRITICAL Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter. | Dec 13, 2017 | 9.8 | 43 | NO | YES |
CVE-2018-6868MEDIUM Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Profile Field parameter. | Feb 23, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Groupon Clone Script Project.
Media articles that mention a CVE ID that affects a product developed by Groupon Clone Script Project — matched by CVE ID, not by vendor name.