Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Iscripts

First CVE: Oct 6, 2007Active for: 19 yearsTotal CVEs: 29
40.2
VTI Score
Medium

Iscripts maintains a focused portfolio of web-based e-commerce, social networking, and hosting platforms that attract a meaningful volume of vulnerability disclosures relative to their product count, reflecting their role in server-side application deployments. The vulnerability profile is characterized by a pronounced tendency toward public exploit availability, paired with a moderate share of critical-severity outcomes, driven by recurring application-layer weakness classes: SQL injection, cross-site scripting, cross-site request forgery, and path traversal vulnerabilities that are endemic to server-side web applications handling user input and file operations. The exposure concentrates across products such as eSwap, SocialWare, AutoHoster, EasyCreate, and MultiCart, each presenting similar input-handling and access-control attack surfaces. Defenders should treat this vendor's advisories as requiring prompt patching in production environments, particularly where these platforms face the internet; live exploitation activity, severity distribution, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Iscripts over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2007
18 years ago
Most Recent CVE
May 25, 2018
2,983 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-2624HIGH
Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) val
Jul 2, 20107.533NOYES
CVE-2013-7189HIGH
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransf
Dec 20, 20137.532NOYES
CVE-2010-5036HIGH
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.
Nov 2, 20117.532NOYES
CVE-2010-4980HIGH
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
Nov 1, 20117.532NOYES
CVE-2010-2853HIGH
SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the product_id parameter.
Jul 25, 20107.532NOYES
CVE-2010-4983HIGH
SQL injection vulnerability in profile.php in iScripts CyberMatch 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Nov 1, 20117.531NOYES
CVE-2018-11373CRITICAL
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
May 22, 20189.830NONO
CVE-2018-9235MEDIUM
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
Apr 4, 20186.130NOYES
CVE-2010-5034HIGH
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.
Nov 2, 20117.530NOYES
CVE-2008-1859HIGH
SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.
Apr 16, 20087.529NOYES
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
48%
45%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (48.3%)
Unknown15 (51.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (48.3%)
High0 (0.0%)
Unknown15 (51.7%)
User Interaction
None4 (13.8%)
Unknown15 (51.7%)
Required10 (34.5%)
Privileges Required
Low4 (13.8%)
High3 (10.3%)
None7 (24.1%)
Unknown15 (51.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
18 CVEs
62.1% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Iscripts.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Iscripts — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Iscripts's Products

View all 1 CNAs →

Top CWEs