Scriptsez has a modest but focused portfolio of web-based applications including blogging, image-downloading, polling, and voting tools, where vulnerabilities recur persistently across multiple products. The vendor's durable exposure concentrates in application-layer input-handling and request-validation weaknesses—cross-site scripting, path traversal, SQL injection, and cross-site request forgery—reflecting the classic attack surface of server-side web applications with insufficient input sanitization and state protection. While the volume of disclosures is limited relative to large platform vendors, the prevalence of public exploit code for vulnerabilities in this class is notably high, making remediation and version tracking important for defenders deploying these tools. Organizations running Scriptsez applications should prioritize patching releases addressing input-validation and CSRF mitigations, and should treat the vendor's advisories as applicable to multiple products simultaneously. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scriptsez over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0983HIGH SQL injection vulnerability in Scriptsez.net Ez Album allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php. | Feb 2, 2012 | 7.5 | 30 | NO | YES |
CVE-2009-4683HIGH Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id para | Mar 10, 2010 | 7.5 | 28 | NO | YES |
CVE-2007-0518HIGH Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded pas | Jan 26, 2007 | 7.5 | 28 | NO | YES |
CVE-2009-4826MEDIUM Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for r | Apr 27, 2010 | 6.8 | 26 | NO | YES |
CVE-2009-4385MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the authentication of arbitrary users for requ | Dec 22, 2009 | 6.8 | 26 | NO | YES |
CVE-2009-3601MEDIUM Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote | Oct 8, 2009 | 4.3 | 24 | NO | YES |
CVE-2008-6112MEDIUM Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a detail action to (1) | Feb 11, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-6089MEDIUM Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a downloa | Feb 6, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-5218MEDIUM ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords. | Nov 25, 2008 | 5.0 | 23 | NO | YES |
CVE-2008-2116MEDIUM Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) te a | May 8, 2008 | 4.4 | 22 | NO | YES |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scriptsez.
Media articles that mention a CVE ID that affects a product developed by Scriptsez — matched by CVE ID, not by vendor name.