Jevontech operates a focused line of web-based communication and social-networking software, with its primary exposure centered on the phpEnPals product. The observed vulnerability pattern reflects characteristic input-handling weaknesses in web applications, particularly SQL injection, which underscores the importance of parameterized queries and input validation in this class of software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jevontech over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0074HIGH SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1. | Jan 4, 2006 | 7.5 | 29 | NO | YES |
CVE-2009-1814HIGH SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector i | May 29, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jevontech.
Media articles that mention a CVE ID that affects a product developed by Jevontech — matched by CVE ID, not by vendor name.