Rivetcode's vulnerability profile centers on RivetTracker, a focused project-management and issue-tracking application, where the durable signal points to input-handling weaknesses in database queries. The observed exposure recurs through SQL injection flaws, reflecting the application's reliance on direct database interaction and the need for rigorous parameterization of user-supplied input.
The number and severity of CVEs published that impact products developed by Rivetcode over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4996HIGH Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) | Sep 19, 2012 | 7.5 | 32 | NO | YES |
CVE-2012-4993HIGH torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact. | Sep 19, 2012 | 7.5 | 32 | NO | YES |
RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php. | Sep 11, 2009 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rivetcode.
Media articles that mention a CVE ID that affects a product developed by Rivetcode — matched by CVE ID, not by vendor name.