Nicplex develops e-commerce and content management products including PlexCart and Plexum, which present a modest application footprint centered on web-based catalog and transaction handling. The recurring signal reflects input-validation weaknesses, particularly SQL injection, characteristic of direct database interaction in web commerce platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nicplex over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1947HIGH Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and | Apr 20, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-1949HIGH SQL injection vulnerability in plexcart.pl in NicPlex PlexCart X3 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | Apr 20, 2006 | 7.5 | 19 | NO | NO |
CVE-2005-4315HIGH SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the ( | Dec 17, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nicplex.
Media articles that mention a CVE ID that affects a product developed by Nicplex — matched by CVE ID, not by vendor name.