Jce Tech's vulnerability profile clusters around a collection of PHP-based web applications and content-integration tools, including calendar scripts, video platforms, affiliate feed parsers, and e-commerce templates that serve small- to medium-sized web publishers and merchants. The vendor's disclosures recur across these modestly represented product lines; current severity, exploitation activity, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jce Tech over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2461HIGH SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter. | Jun 25, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-2460HIGH SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id paramet | Jun 25, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-0375HIGH SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrary SQL commands via the cat parameter. | Jan 21, 2010 | 7.5 | 29 | NO | YES |
CVE-2010-0380MEDIUM install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application settings via a direct request. NO | Jan 22, 2010 | 5.0 | 23 | NO | YES |
CVE-2010-0376MEDIUM Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to inject arbitrary web script or HTML via th | Jan 21, 2010 | 4.3 | 21 | NO | YES |
CVE-2009-3196MEDIUM Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. | Sep 15, 2009 | 4.3 | 21 | NO | YES |
CVE-2009-3195MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to | Sep 15, 2009 | 4.3 | 21 | NO | YES |
CVE-2009-3194MEDIUM Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Sep 15, 2009 | 4.3 | 21 | NO | YES |
CVE-2014-8752MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in view.php in JCE-Tech PHP Video Script (aka Video Niche Script) 4.0 allow remote attackers to inject arbitrary web script or H | Dec 31, 2014 | 4.3 | 14 | NO | NO |
CVE-2009-3198MEDIUM Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to inject arbitrary web script or HTML via th | Sep 15, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jce Tech.
Media articles that mention a CVE ID that affects a product developed by Jce Tech — matched by CVE ID, not by vendor name.