The Paid To Read Script Project maintains a niche web application framework, with its vulnerability footprint concentrated in the core paid-to-read-script product and dominated by application-layer input-handling and authentication weaknesses such as SQL injection, cross-site scripting, improper authentication, and sensitive information exposure. These classes are characteristic of web application architecture and reflect the product's role in handling user input and managing access controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paid To Read Script Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17651CRITICAL Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter. | Dec 18, 2017 | 9.8 | 43 | NO | YES |
CVE-2017-17779CRITICAL Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter. | Dec 20, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-17777CRITICAL Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php | Dec 20, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-17776MEDIUM Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter. | Dec 20, 2017 | 5.3 | 19 | NO | NO |
CVE-2017-17778MEDIUM Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter. | Dec 20, 2017 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paid To Read Script Project.
Media articles that mention a CVE ID that affects a product developed by Paid To Read Script Project — matched by CVE ID, not by vendor name.