Inoutscripts operates a diverse portfolio of web-facing applications spanning blockchain exchanges, hospitality platforms, ad serving, and search infrastructure, creating multiple attack surfaces centered on user input handling and data interaction. Its vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with the recurring exposure concentrated in SQL injection and cross-site scripting weaknesses that are characteristic of web applications lacking robust input sanitization and output encoding. Defenders treating this vendor's advisories should prioritize patching instances exposed to untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inoutscripts over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2988HIGH A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers | Jun 1, 2007 | 7.5 | 31 | NO | YES |
CVE-2019-25528CRITICAL Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the | Mar 12, 2026 | 9.1 | 28 | NO | NO |
CVE-2019-25527CRITICAL Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the | Mar 12, 2026 | 9.1 | 28 | NO | NO |
CVE-2019-25526CRITICAL Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the | Mar 12, 2026 | 9.1 | 28 | NO | NO |
CVE-2019-25525CRITICAL Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the | Mar 12, 2026 | 9.1 | 28 | NO | NO |
CVE-2009-3223MEDIUM SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | Sep 16, 2009 | 6.5 | 27 | NO | YES |
CVE-2022-31488HIGH Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection. | May 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-34988MEDIUM Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js. | Jul 26, 2022 | 5.4 | 19 | NO | NO |
CVE-2022-31489HIGH Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection. | May 23, 2022 | 7.5 | 19 | NO | NO |
CVE-2022-31487HIGH Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection. | May 23, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inoutscripts.
Media articles that mention a CVE ID that affects a product developed by Inoutscripts — matched by CVE ID, not by vendor name.