Ipublishmedia's vulnerability footprint centers on a web-based advertising and publishing platform, AdPortal, with a durable signal rooted in application-layer code-generation and input-handling weaknesses including code injection and cross-site scripting. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipublishmedia over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50658CRITICAL Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateus | Jan 7, 2025 | 9.8 | 32 | NO | NO |
CVE-2024-50660CRITICAL File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality | Jan 7, 2025 | 9.8 | 29 | NO | NO |
CVE-2024-50659MEDIUM Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.ht | Jan 7, 2025 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipublishmedia.
Media articles that mention a CVE ID that affects a product developed by Ipublishmedia — matched by CVE ID, not by vendor name.