The Hot Scripts Clone Project develops a web-based application that exhibits a consistent pattern of input-handling vulnerabilities, particularly cross-site scripting, SQL injection, and improper input validation. These are characteristic weaknesses of web applications that process user-supplied data without adequate sanitization and parameterization; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hot Scripts Clone Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17612CRITICAL Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter. | Dec 13, 2017 | 9.8 | 42 | NO | YES |
CVE-2018-6903HIGH PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-ma | Apr 12, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-6878MEDIUM Cross Site Scripting (XSS) exists in the review section in PHP Scripts Mall Hot Scripts Clone Script Classified 3.1 via the title or description field. | Feb 9, 2018 | 5.4 | 19 | NO | NO |
CVE-2018-7650MEDIUM PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add New" function for a Management User. Within the "Add New" s | Mar 6, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hot Scripts Clone Project.
Media articles that mention a CVE ID that affects a product developed by Hot Scripts Clone Project — matched by CVE ID, not by vendor name.