Stivasoft develops a suite of PHP-based web applications including file-sharing, newsletter, event-booking, and rating scripts that rely on user input handling and server-side rendering. The vulnerability footprint across these products centers on cross-site scripting and related input-neutralization issues endemic to web applications that process and display user-supplied content without sufficient output encoding. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stivasoft over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12811MEDIUM PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item. | Dec 30, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-12813MEDIUM PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section. | Dec 30, 2017 | 6.1 | 20 | NO | NO |
CVE-2017-12812MEDIUM PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab. | Dec 30, 2017 | 6.1 | 17 | NO | NO |
CVE-2017-12810MEDIUM PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel. | Dec 30, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stivasoft.
Media articles that mention a CVE ID that affects a product developed by Stivasoft — matched by CVE ID, not by vendor name.