Salephpscripts develops a web-directory application that exhibits a pattern of application-layer input-handling vulnerabilities, particularly SQL injection and cross-site scripting flaws characteristic of script-based web software. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Salephpscripts over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3552CRITICAL The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated use | Jun 13, 2024 | 9.8 | 75 | NO | YES |
CVE-2024-3673CRITICAL The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues. | Aug 30, 2024 | 9.1 | 39 | NO | YES |
CVE-2023-2201HIGH The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.6.8 due to insufficient escaping on the user su | Jun 2, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-3669MEDIUM The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting whi | Jul 30, 2024 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Salephpscripts.
Media articles that mention a CVE ID that affects a product developed by Salephpscripts — matched by CVE ID, not by vendor name.