Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Softbizscripts

First CVE: Nov 26, 2005Active for: 21 yearsTotal CVEs: 27
43.7
VTI Score
High

Softbizscripts develops a portfolio of web-based business scripts including image galleries, classifieds, dating platforms, freelancer marketplaces, and job-recruitment systems, products typically deployed on shared hosting and small-business web servers. The vendor's vulnerability profile is characterized by a strong tendency toward public exploit availability across its disclosures, reflecting the appeal of these commodity web applications to both security researchers and operators of automated scanning tools. Exposure recurs persistently through SQL injection and cross-site scripting weaknesses in input handling and output generation, vulnerability classes endemic to legacy PHP-based web script development where parameterization and output encoding practices were inconsistently applied. Defenders operating or supporting these scripts should prioritize input validation and output encoding hardening, apply available patches promptly, and consider isolating these applications behind web application firewalls; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Softbizscripts over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 26, 2005
20 years ago
Most Recent CVE
Oct 8, 2011
5,403 days ago

Products(20 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4905HIGH
SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter.
Oct 8, 20117.530NOYES
CVE-2010-0758HIGH
SQL injection vulnerability in news_desc.php in Softbiz Jobs allows remote attackers to execute arbitrary SQL commands via the id parameter.
Feb 27, 20107.529NOYES
CVE-2009-2790HIGH
SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap
Aug 17, 20097.529NOYES
CVE-2005-3938HIGH
SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php,
Dec 1, 20057.529NOYES
CVE-2005-3879HIGH
Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sbres_id parameter
Nov 29, 20057.529NOYES
CVE-2005-3817HIGH
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in se
Nov 26, 20057.529NOYES
CVE-2008-2874HIGH
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vec
Jun 26, 20087.528NOYES
CVE-2008-1050HIGH
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter.
Feb 27, 20087.528NOYES
CVE-2007-6125HIGH
SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.
Nov 26, 20077.528NOYES
CVE-2007-5996HIGH
SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related iss
Nov 15, 20077.528NOYES
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
41%
59%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown27 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown27 (100.0%)
User Interaction
None0 (0.0%)
Unknown27 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown27 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
25 CVEs
92.6% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Softbizscripts.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Softbizscripts — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Softbizscripts's Products

View all 1 CNAs →

Top CWEs