Maian Script World maintains a narrow portfolio of web-facing applications, including file upload, search, and blogging utilities, centered on authentication and input-handling vulnerabilities such as improper authentication controls and cross-site scripting. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maian Script World over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32172CRITICAL Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. | Oct 7, 2021 | 9.8 | 84 | NO | YES |
CVE-2008-7086HIGH Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin. | Aug 26, 2009 | 7.5 | 32 | NO | YES |
CVE-2008-3317HIGH admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie. | Jul 25, 2008 | 7.5 | 31 | NO | YES |
CVE-2008-3321HIGH admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie. | Jul 25, 2008 | 7.5 | 31 | NO | YES |
CVE-2006-1334MEDIUM Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and | Mar 21, 2006 | 6.4 | 26 | NO | YES |
CVE-2008-2202MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/adm | May 14, 2008 | 4.3 | 21 | NO | YES |
CVE-2014-10004HIGH SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jan 13, 2015 | 7.5 | 20 | NO | NO |
CVE-2008-2203HIGH SQL injection vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action. | May 14, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-2205HIGH SQL injection vulnerability in index.php in Maian Music 1.1 allows remote attackers to execute arbitrary SQL commands via the album parameter in an album action. | May 14, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-2208HIGH SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action. | May 14, 2008 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maian Script World.
Media articles that mention a CVE ID that affects a product developed by Maian Script World — matched by CVE ID, not by vendor name.