Maianscriptworld's vulnerability profile centers on a modest line of web-based applications including file uploaders, shopping carts, greeting systems, and search utilities—products typically deployed in shared hosting and small-business environments. The durable signal across its disclosures is a strong tendency toward public exploit availability, paired with recurring input-handling and authentication vulnerabilities characteristic of web applications: cross-site scripting, SQL injection, CSRF, and improper credential validation recur across the product line and often involve exposure of sensitive data. These weakness classes reflect the inherent risks of user-input processing and session management in older PHP-based frameworks, and the exploit-availability pattern suggests the product line has attracted sustained security tool development. Defenders deploying Maianscriptworld products should prioritize input sanitization and parameterized queries, maintain strict access controls, and consider whether modern alternatives offer better security posture; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maianscriptworld over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32172CRITICAL Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. | Oct 7, 2021 | 9.8 | 84 | NO | YES |
CVE-2008-7086HIGH Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin. | Aug 26, 2009 | 7.5 | 32 | NO | YES |
CVE-2008-3317HIGH admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary search_cookie cookie. | Jul 25, 2008 | 7.5 | 31 | NO | YES |
CVE-2008-3321HIGH admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie. | Jul 25, 2008 | 7.5 | 31 | NO | YES |
CVE-2006-1334MEDIUM Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and | Mar 21, 2006 | 6.4 | 26 | NO | YES |
CVE-2008-2202MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/adm | May 14, 2008 | 4.3 | 21 | NO | YES |
CVE-2014-10004HIGH SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jan 13, 2015 | 7.5 | 20 | NO | NO |
CVE-2008-2203HIGH SQL injection vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action. | May 14, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-2205HIGH SQL injection vulnerability in index.php in Maian Music 1.1 allows remote attackers to execute arbitrary SQL commands via the album parameter in an album action. | May 14, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-2208HIGH SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action. | May 14, 2008 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maianscriptworld.
Media articles that mention a CVE ID that affects a product developed by Maianscriptworld — matched by CVE ID, not by vendor name.