Ofofonobsdev develops the HubBank product, a web-based banking application whose vulnerability profile centers on input-handling and file-upload mechanisms. The recurring weakness classes—SQL injection, cross-site scripting, and unrestricted file uploads—reflect the attack surface typical of web-facing financial applications and their reliance on robust input validation and access controls. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ofofonobsdev over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4306HIGH Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious PHP files via upload document fi | Apr 29, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-4309HIGH SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different e | Apr 29, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-4308HIGH SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different e | Apr 29, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-4307HIGH SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different e | Apr 29, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-4310MEDIUM Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration an | Apr 29, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ofofonobsdev.
Media articles that mention a CVE ID that affects a product developed by Ofofonobsdev — matched by CVE ID, not by vendor name.