Quirm maintains a niche portfolio of web applications and libraries—including Saxon, ESPG, Simple PHP Newsletter, and Zenlite—that handle input processing and data exposure across modest deployments. The vendor's vulnerability profile is characterized by a recurring pattern of web-layer input-handling and information-disclosure issues: path traversal, cross-site scripting, SQL injection, and sensitive data exposure, all of which are endemic to web application development and frequently acquire public exploit code. Defenders tracking this vendor should prioritize input validation and output encoding reviews in these products; live severity and current exploit-availability figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quirm over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0331HIGH Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attackers to read arbitrary files via a .. (dot dot) in the file p | Jan 29, 2009 | 7.8 | 29 | NO | YES |
CVE-2007-4863MEDIUM SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter. | Oct 30, 2007 | 6.8 | 28 | NO | YES |
CVE-2009-0340MEDIUM Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php a | Jan 29, 2009 | 6.8 | 27 | NO | YES |
CVE-2007-4862MEDIUM Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[news_url] parameter. | Oct 30, 2007 | 4.3 | 21 | NO | YES |
CVE-2011-3854MEDIUM Cross-site scripting (XSS) vulnerability in the ZenLite theme before 4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | Sep 28, 2011 | 4.3 | 17 | NO | NO |
CVE-2007-4861MEDIUM SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array paramete | Oct 30, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quirm.
Media articles that mention a CVE ID that affects a product developed by Quirm — matched by CVE ID, not by vendor name.