Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpscriptsmall

First CVE: Oct 4, 2018Active for: 8 yearsTotal CVEs: 8

Phpscriptsmall develops a small portfolio of web application templates and clone scripts, including marketplace platforms such as Fiverr and OLX clones, gift-shop applications, and content-publishing systems that operate at the application tier. Vulnerabilities affecting these products skew strongly toward critical-severity outcomes and recur through a durable set of web-layer weaknesses: cross-site scripting, SQL injection, and cross-site request forgery, each of which can lead to data compromise or unauthorized actions in multi-user web environments. Defenders deploying these scripts should prioritize input validation and output encoding across the application stack; live severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpscriptsmall over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2018
7 years ago
Most Recent CVE
Apr 5, 2026
110 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-25676CRITICAL
Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters
Apr 5, 20269.831NONO
CVE-2019-25680CRITICAL
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throug
Apr 5, 20269.830NONO
CVE-2019-25444CRITICAL
Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parame
Feb 20, 20269.129NONO
CVE-2019-25668HIGH
News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID par
Apr 5, 20268.227NONO
CVE-2019-9062HIGH
PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
Feb 23, 20198.025NONO
CVE-2019-25445MEDIUM
Fiverr Clone Script 1.2.2 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the keyword parameter. Att
Feb 20, 20266.121NONO
CVE-2018-16326MEDIUM
PHP Scripts Mall Olx Clone 3.4.2 has XSS.
Oct 4, 20186.121NONO
CVE-2018-16456MEDIUM
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has XSS via the Listings Search feature.
Oct 4, 20186.120NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
25%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (50.0%)
Unknown0 (0.0%)
Required4 (50.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpscriptsmall.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpscriptsmall — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpscriptsmall's Products

View all 2 CNAs →

Top CWEs