Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Snitz Communications

First CVE: Jun 18, 2002Active for: 24 yearsTotal CVEs: 25
43.3
VTI Score
High

Snitz Communications maintains a narrowly scoped portfolio centered around web-based forum software, particularly Snitz Forums 2000 and its associated components, which despite limited product breadth achieved notable visibility in early-stage web community platforms. The vendor's vulnerability profile is characterized by a pronounced tendency toward public exploit availability, reflecting the accessibility and attractiveness of forum software as a target for web-based attacks. The recurring weakness classes, dominated by cross-site scripting, SQL injection, improper input validation, and information exposure, are endemic to web applications that handle user-generated content and database interactions without robust input sanitization. Defenders deploying or maintaining legacy Snitz-based communities should prioritize isolation and access controls, as the public availability of exploit tooling elevates the practical risk even in environments with deferred patching timelines. Current severity, exploitation activity, and vulnerability counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Snitz Communications over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2002
24 years ago
Most Recent CVE
Oct 8, 2012
5,037 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-5603CRITICAL
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of thi
Oct 30, 20069.834NOYES
CVE-2012-5313HIGH
SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter.
Oct 8, 20127.531NOYES
CVE-2002-0329HIGH
Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG t
Jun 25, 20027.530NOYES
CVE-2007-6240HIGH
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.
Dec 5, 20077.528NOYES
CVE-2007-1023HIGH
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Feb 21, 20077.528NOYES
CVE-2003-0492MEDIUM
Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.
Aug 7, 20036.828NOYES
CVE-2002-0607HIGH
members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName,
Jun 18, 20027.528NOYES
CVE-2003-0494HIGH
password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modifie
Aug 7, 200310.026NONO
CVE-2003-0493HIGH
Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.
Aug 7, 200310.025NONO
CVE-2008-0135MEDIUM
Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a di
Jan 8, 20085.023NOYES
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
56%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (4.0%)
Unknown24 (96.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.0%)
High0 (0.0%)
Unknown24 (96.0%)
User Interaction
None1 (4.0%)
Unknown24 (96.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (4.0%)
Unknown24 (96.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
52.0% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Snitz Communications.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Snitz Communications — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Snitz Communications's Products

View all 1 CNAs →

Top CWEs