Softbizscripts develops a portfolio of web-based business scripts including image galleries, classifieds, dating platforms, freelancer marketplaces, and job-recruitment systems, products typically deployed on shared hosting and small-business web servers. The vendor's vulnerability profile is characterized by a strong tendency toward public exploit availability across its disclosures, reflecting the appeal of these commodity web applications to both security researchers and operators of automated scanning tools. Exposure recurs persistently through SQL injection and cross-site scripting weaknesses in input handling and output generation, vulnerability classes endemic to legacy PHP-based web script development where parameterization and output encoding practices were inconsistently applied. Defenders operating or supporting these scripts should prioritize input validation and output encoding hardening, apply available patches promptly, and consider isolating these applications behind web application firewalls; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softbizscripts over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4905HIGH SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execute arbitrary SQL commands via the sbiz_id parameter. | Oct 8, 2011 | 7.5 | 30 | NO | YES |
CVE-2010-0758HIGH SQL injection vulnerability in news_desc.php in Softbiz Jobs allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 27, 2010 | 7.5 | 29 | NO | YES |
CVE-2009-2790HIGH SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap | Aug 17, 2009 | 7.5 | 29 | NO | YES |
CVE-2005-3938HIGH SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, | Dec 1, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-3879HIGH Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sbres_id parameter | Nov 29, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-3817HIGH Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in se | Nov 26, 2005 | 7.5 | 29 | NO | YES |
CVE-2008-2874HIGH SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vec | Jun 26, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-1050HIGH SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter. | Feb 27, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-6125HIGH SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter. | Nov 26, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-5996HIGH SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related iss | Nov 15, 2007 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softbizscripts.
Media articles that mention a CVE ID that affects a product developed by Softbizscripts — matched by CVE ID, not by vendor name.