Post Affiliate Pro is an affiliate management and commission-tracking platform whose vulnerability footprint remains narrowly scoped to the single product. The recurring signal centers on application-level input and business-logic handling, consistent with web-based affiliate software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Post Affiliate Pro over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3909HIGH SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter. | Nov 30, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-3910MEDIUM merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly | Nov 30, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Post Affiliate Pro.
Media articles that mention a CVE ID that affects a product developed by Post Affiliate Pro — matched by CVE ID, not by vendor name.