Itechscripts maintains a focused portfolio of web-based business applications including auction platforms, classified-listing systems, travel booking tools, and project-management software, which collectively present a moderate but concentrated attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the maturity of web-application attack tooling and the value of these web-facing platforms as targets. The exposure recurs persistently through application-layer weaknesses including SQL injection, cross-site scripting, and improper authentication, which are characteristic of server-side script and form-handling complexity in this product class. Defenders should treat updates from this vendor as high-priority and inventory deployed instances, particularly internet-facing deployments; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Itechscripts over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15963CRITICAL iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter. | Oct 29, 2017 | 9.8 | 40 | NO | YES |
CVE-2012-4281HIGH Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL commands via the hid parameter to (1) holiday.php or (2) holiday_bo | Aug 13, 2012 | 7.5 | 32 | NO | YES |
CVE-2017-20138CRITICAL A vulnerability was found in Itech Auction Script 6.49. It has been classified as critical. This affects an unknown part of the file /mcategory.php. The manipulation of the argumen | Jul 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-20135CRITICAL A vulnerability classified as critical was found in Itech Dating Script 3.26. Affected by this vulnerability is an unknown functionality of the file /see_more_details.php. The mani | Jul 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-20134CRITICAL A vulnerability, which was classified as critical, has been found in Itech Freelancer Script 5.13. Affected by this issue is some unknown functionality of the file /category.php. T | Jul 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-20133CRITICAL A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The manipulation leads to improper au | Jul 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-20132CRITICAL A vulnerability was found in Itech Multi Vendor Script 6.49 and classified as critical. This issue affects some unknown processing of the file /multi-vendor-shopping-script/product | Jul 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-20131CRITICAL A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function of the file /news-portal-script/information.php. The manipu | Jul 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-20130CRITICAL A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /real-estate-sc | Jul 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2012-4265HIGH SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Aug 13, 2012 | 7.5 | 31 | NO | YES |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Itechscripts.
Media articles that mention a CVE ID that affects a product developed by Itechscripts — matched by CVE ID, not by vendor name.