Iscripts maintains a focused portfolio of web-based e-commerce, social networking, and hosting platforms that attract a meaningful volume of vulnerability disclosures relative to their product count, reflecting their role in server-side application deployments. The vulnerability profile is characterized by a pronounced tendency toward public exploit availability, paired with a moderate share of critical-severity outcomes, driven by recurring application-layer weakness classes: SQL injection, cross-site scripting, cross-site request forgery, and path traversal vulnerabilities that are endemic to server-side web applications handling user input and file operations. The exposure concentrates across products such as eSwap, SocialWare, AutoHoster, EasyCreate, and MultiCart, each presenting similar input-handling and access-control attack surfaces. Defenders should treat this vendor's advisories as requiring prompt patching in production environments, particularly where these platforms face the internet; live exploitation activity, severity distribution, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iscripts over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2624HIGH Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) val | Jul 2, 2010 | 7.5 | 33 | NO | YES |
CVE-2013-7189HIGH Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransf | Dec 20, 2013 | 7.5 | 32 | NO | YES |
CVE-2010-5036HIGH SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. | Nov 2, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4980HIGH SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | Nov 1, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-2853HIGH SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the product_id parameter. | Jul 25, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-4983HIGH SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 1, 2011 | 7.5 | 31 | NO | YES |
CVE-2018-11373CRITICAL iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. | May 22, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-9235MEDIUM iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php. | Apr 4, 2018 | 6.1 | 30 | NO | YES |
CVE-2010-5034HIGH SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter. | Nov 2, 2011 | 7.5 | 30 | NO | YES |
CVE-2008-1859HIGH SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action. | Apr 16, 2008 | 7.5 | 29 | NO | YES |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iscripts.
Media articles that mention a CVE ID that affects a product developed by Iscripts — matched by CVE ID, not by vendor name.