Virtuenetz develops a focused suite of web-based applications including online testing, e-commerce, content management, and classifieds platforms that operate in internet-facing deployment contexts. The vendor's vulnerability profile centers on application-layer input-handling issues, particularly SQL injection and cross-site scripting flaws that recur across its product line and reflect the parsing and output-encoding demands of web application development. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Virtuenetz over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2021HIGH SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter. | Jun 9, 2009 | 7.5 | 42 | NO | YES |
CVE-2009-2019HIGH SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter. | Jun 9, 2009 | 7.5 | 35 | NO | YES |
CVE-2009-2017HIGH SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Jun 9, 2009 | 7.5 | 35 | NO | YES |
CVE-2009-2016HIGH SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Jun 9, 2009 | 7.5 | 34 | NO | YES |
CVE-2009-2392HIGH SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute arbitrary SQL commands via the tid parameter. | Jul 9, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2020MEDIUM Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via the nid parameter. | Jun 9, 2009 | 4.3 | 27 | NO | YES |
CVE-2009-2393MEDIUM admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspeci | Jul 9, 2009 | 6.5 | 26 | NO | YES |
CVE-2010-4923HIGH SQL injection vulnerability in book/detail.php in Virtue Netz Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the bid parameter. | Oct 9, 2011 | 7.5 | 22 | NO | NO |
CVE-2010-4908HIGH SQL injection vulnerability in detail.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the prodid parameter. | Oct 8, 2011 | 7.5 | 21 | NO | NO |
CVE-2009-2391MEDIUM Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter | Jul 9, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virtuenetz.
Media articles that mention a CVE ID that affects a product developed by Virtuenetz — matched by CVE ID, not by vendor name.