Maxdev develops a narrowly scoped set of web-based productivity and gallery applications, including the MD Pro suite and MyEGallery, that occupy a more prominent niche than their modest disclosure volume might suggest. The vendor's vulnerability profile is characterized by a strong tendency toward public exploit availability, coupled with recurring application-layer weaknesses—particularly SQL injection, path traversal, and sensitive-data exposure—that are typical of web-facing software handling user input and file access. These weakness classes reflect the attack surface inherent to web applications that manage user content and database queries, and the elevated exploit availability underscores the appeal of such flaws to researchers and attackers. Defenders should prioritize patching cycles for Maxdev products where they are deployed as internet-accessible services, particularly where they handle authentication or store sensitive user data. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maxdev over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2885HIGH The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers t | Sep 14, 2005 | 7.5 | 34 | NO | YES |
CVE-2006-6869HIGH Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allo | Dec 31, 2006 | 9.3 | 33 | NO | YES |
CVE-2009-2618HIGH SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a r | Jul 27, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-7038HIGH SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.p | Aug 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2307HIGH SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter | Jul 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-0728HIGH SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a sh | Feb 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-5222HIGH SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP h | Oct 5, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-3938HIGH SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid param | Jul 21, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-0623HIGH SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter. | Jan 31, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-7112MEDIUM Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demons | Mar 6, 2007 | 6.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maxdev.
Media articles that mention a CVE ID that affects a product developed by Maxdev — matched by CVE ID, not by vendor name.