Msaad1999's vulnerability footprint centers on web applications including a social media website and PHP-based login systems, with the durable signal concentrated on cross-site scripting vulnerabilities arising from improper input neutralization during web page generation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Msaad1999 over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38875MEDIUM A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by | Sep 20, 2023 | 6.1 | 28 | NO | YES |
CVE-2024-26473MEDIUM A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll para | Feb 29, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-26472MEDIUM KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in th | Feb 29, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-38876MEDIUM A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by | Sep 20, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-26471MEDIUM A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parame | Feb 29, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Msaad1999.
Media articles that mention a CVE ID that affects a product developed by Msaad1999 — matched by CVE ID, not by vendor name.