Myiosoft maintains a narrow portfolio of web-based portal and content-management applications, including EasyCalendar, EasyBookmarker, EasyNews, AjaxPortal, and EasyDynamicPages, that expose input-handling and code-generation attack surfaces. Despite the modest product count, these applications frequently acquire public exploit code, indicating sustained researcher and attacker interest. The vulnerability profile clusters consistently around input-validation weaknesses—SQL injection, cross-site scripting, code injection, and path traversal—that are characteristic of web applications built without systematic input sanitization and code-generation guardrails. Defenders deploying these products should prioritize patching cycles and input-layer hardening; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myiosoft over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3345MEDIUM SQL injection vulnerability in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a, when magic_quotes_gpc is disabled, allows remote attackers | Jul 28, 2008 | 6.8 | 31 | NO | YES |
CVE-2008-1346HIGH SQL injection vulnerability in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allows remote attackers to execute arbitrary SQL commands via the catid p | Mar 17, 2008 | 7.5 | 31 | NO | YES |
CVE-2008-3343HIGH SQL injection vulnerability in staticpages/easypublish/index.php in MyioSoft EasyPublish 3.0tr (trial edition) allows remote attackers to execute arbitrary SQL commands via the rea | Jul 28, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-1651HIGH Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | Apr 2, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-1344HIGH Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in a dayview a | Mar 17, 2008 | 7.5 | 29 | NO | YES |
CVE-2009-1509HIGH SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | May 1, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5655HIGH Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link paramet | Dec 17, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5654HIGH SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, a | Dec 17, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5652HIGH SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, | Dec 17, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5651HIGH SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the Parent par | Dec 17, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myiosoft.
Media articles that mention a CVE ID that affects a product developed by Myiosoft — matched by CVE ID, not by vendor name.