Torrenttrader is a modestly represented torrent-management platform with recurring vulnerabilities centered on web-application input handling. The exposure across its core product line reflects a durable pattern of cross-site scripting, SQL injection, path traversal, and CSRF weaknesses typical of server-side web applications that handle user-generated content and file operations. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Torrenttrader over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2158HIGH account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a b | Jun 22, 2009 | 7.5 | 29 | NO | YES |
CVE-2007-5311HIGH Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote attackers to include and execute arbitrary local files via a .. | Oct 9, 2007 | 7.5 | 29 | NO | YES |
CVE-2008-6418HIGH SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the info_hash parameter. | Mar 6, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-4494HIGH SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id paramet | Oct 9, 2008 | 7.5 | 28 | NO | YES |
CVE-2009-2159MEDIUM backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a | Jun 22, 2009 | 6.4 | 26 | NO | YES |
CVE-2009-2157MEDIUM Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the origmsg parameter to account-inb | Jun 22, 2009 | 6.5 | 26 | NO | YES |
CVE-2009-2161MEDIUM Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and exe | Jun 22, 2009 | 5.1 | 23 | NO | YES |
CVE-2009-2160MEDIUM TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote | Jun 22, 2009 | 5.0 | 23 | NO | YES |
CVE-2007-4435HIGH Multiple SQL injection vulnerabilities in TorrentTrader before 1.07 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) account-inbox.php, (2 | Aug 20, 2007 | 7.5 | 22 | NO | NO |
CVE-2008-1173MEDIUM Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | Mar 6, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Torrenttrader.
Media articles that mention a CVE ID that affects a product developed by Torrenttrader — matched by CVE ID, not by vendor name.