Scubez develops a classified-listings application (Posty Readymade Classifieds) that handles user-generated content and database interactions across a web interface. The vendor's observed vulnerability exposure centers on input-handling and access-control weaknesses, including SQL injection, cross-site scripting, and improper permission assignment for critical resources, which are characteristic of web applications that process untrusted user input and manage authentication boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scubez over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17111CRITICAL Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request. | Dec 11, 2017 | 9.8 | 46 | NO | YES |
CVE-2017-17567HIGH Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter. | Dec 13, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-17568HIGH Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obta | Dec 13, 2017 | 7.5 | 22 | NO | NO |
CVE-2017-17569MEDIUM Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter. | Dec 13, 2017 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scubez.
Media articles that mention a CVE ID that affects a product developed by Scubez — matched by CVE ID, not by vendor name.