Phpscriptsmall develops a small portfolio of web application templates and clone scripts, including marketplace platforms such as Fiverr and OLX clones, gift-shop applications, and content-publishing systems that operate at the application tier. Vulnerabilities affecting these products skew strongly toward critical-severity outcomes and recur through a durable set of web-layer weaknesses: cross-site scripting, SQL injection, and cross-site request forgery, each of which can lead to data compromise or unauthorized actions in multi-user web environments. Defenders deploying these scripts should prioritize input validation and output encoding across the application stack; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpscriptsmall over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25676CRITICAL Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters | Apr 5, 2026 | 9.8 | 31 | NO | NO |
CVE-2019-25680CRITICAL Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throug | Apr 5, 2026 | 9.8 | 30 | NO | NO |
CVE-2019-25444CRITICAL Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parame | Feb 20, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25668HIGH News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID par | Apr 5, 2026 | 8.2 | 27 | NO | NO |
CVE-2019-9062HIGH PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php. | Feb 23, 2019 | 8.0 | 25 | NO | NO |
CVE-2019-25445MEDIUM Fiverr Clone Script 1.2.2 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the keyword parameter. Att | Feb 20, 2026 | 6.1 | 21 | NO | NO |
CVE-2018-16326MEDIUM PHP Scripts Mall Olx Clone 3.4.2 has XSS. | Oct 4, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-16456MEDIUM PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has XSS via the Listings Search feature. | Oct 4, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpscriptsmall.
Media articles that mention a CVE ID that affects a product developed by Phpscriptsmall — matched by CVE ID, not by vendor name.