Preprojects develops a portfolio of web-based classified listings, real-estate, job-board, and advertising portal applications that typically serve small-to-medium business and community use cases. The vendor's vulnerability footprint is characterized by a strong tendency toward public exploit availability, reflecting the accessibility and popularity of these application types as targets for both security research and malicious reconnaissance. Recurring weaknesses cluster around web application fundamentals: SQL injection, cross-site scripting, improper authentication, and input validation failures that are endemic to database-driven web applications and reflect common development challenges in this product category. Defenders deploying these applications should prioritize secure coding practices, input sanitization, and authentication hardening as foundational controls; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Preprojects over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5334HIGH SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter. | Oct 8, 2012 | 7.5 | 32 | NO | YES |
CVE-2010-4776HIGH SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter. | Mar 23, 2011 | 7.5 | 32 | NO | YES |
CVE-2012-5333HIGH SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter. | Oct 8, 2012 | 7.5 | 31 | NO | YES |
CVE-2011-5139HIGH SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter. | Aug 31, 2012 | 7.5 | 30 | NO | YES |
CVE-2008-6230HIGH SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 20, 2009 | 7.5 | 30 | NO | YES |
CVE-2008-6232HIGH Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin". | Feb 20, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6231HIGH Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin". | Feb 20, 2009 | 7.5 | 29 | NO | YES |
CVE-2010-1369HIGH SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter. | Apr 13, 2010 | 7.5 | 28 | NO | YES |
CVE-2008-6887HIGH SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter. | Aug 3, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6798HIGH Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka | May 7, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Preprojects.
Media articles that mention a CVE ID that affects a product developed by Preprojects — matched by CVE ID, not by vendor name.