Newsscriptphp operates a niche web-content management and publishing platform, News Script PHP Pro, that is subject to the common application-layer vulnerabilities affecting server-side web software. The observed weakness classes—cross-site request forgery, cross-site scripting, and SQL injection—reflect input-handling and session-management challenges endemic to PHP-based content systems. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Newsscriptphp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25475CRITICAL SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action. | Nov 24, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-25473MEDIUM SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies. | Nov 24, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-25474MEDIUM SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter. | Nov 24, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-25472MEDIUM SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users. | Nov 24, 2020 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Newsscriptphp.
Media articles that mention a CVE ID that affects a product developed by Newsscriptphp — matched by CVE ID, not by vendor name.