Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Maxdev

First CVE: Sep 7, 2005Active for: 21 yearsTotal CVEs: 21
43.0
VTI Score
High

Maxdev develops a narrowly scoped set of web-based productivity and gallery applications, including the MD Pro suite and MyEGallery, that occupy a more prominent niche than their modest disclosure volume might suggest. The vendor's vulnerability profile is characterized by a strong tendency toward public exploit availability, coupled with recurring application-layer weaknesses—particularly SQL injection, path traversal, and sensitive-data exposure—that are typical of web-facing software handling user input and file access. These weakness classes reflect the attack surface inherent to web applications that manage user content and database queries, and the elevated exploit availability underscores the appeal of such flaws to researchers and attackers. Defenders should prioritize patching cycles for Maxdev products where they are deployed as internet-accessible services, particularly where they handle authentication or store sensitive user data. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Maxdev over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2005
20 years ago
Most Recent CVE
Jan 6, 2010
6,043 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-2885HIGH
The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers t
Sep 14, 20057.534NOYES
CVE-2006-6869HIGH
Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allo
Dec 31, 20069.333NOYES
CVE-2009-2618HIGH
SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a r
Jul 27, 20097.529NOYES
CVE-2008-7038HIGH
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.p
Aug 24, 20097.528NOYES
CVE-2009-2307HIGH
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter
Jul 2, 20097.528NOYES
CVE-2009-0728HIGH
SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a sh
Feb 24, 20097.528NOYES
CVE-2007-5222HIGH
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP h
Oct 5, 20077.528NOYES
CVE-2007-3938HIGH
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid param
Jul 21, 20077.528NOYES
CVE-2007-0623HIGH
SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.
Jan 31, 20077.528NOYES
CVE-2006-7112MEDIUM
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demons
Mar 6, 20076.025NOYES
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
48%
52%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown21 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown21 (100.0%)
User Interaction
None0 (0.0%)
Unknown21 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown21 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
57.1% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Maxdev.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Maxdev — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Maxdev's Products

View all 1 CNAs →

Top CWEs