V Eva maintains a small portfolio of web-based tools and scripts, including a press release distribution script and an affiliate commerce script for PHP environments. The observed vulnerability profile reflects vulnerabilities in these lightweight web-utility products; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by V Eva over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-5047HIGH SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 23, 2011 | 7.5 | 35 | NO | YES |
CVE-2010-2040MEDIUM Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter. | May 25, 2010 | 4.3 | 23 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by V Eva.
Media articles that mention a CVE ID that affects a product developed by V Eva — matched by CVE ID, not by vendor name.