Visualshapers develops web content management and digital asset solutions centered on the EZcontents platform, a product with a notable presence in content-delivery workflows. The vulnerability surface recurs around path-traversal and SQL-injection flaws characteristic of web application input handling, and public exploit code has been developed and distributed for vulnerabilities affecting this vendor. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Visualshapers over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4477HIGH Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empty GLOBALS[rootdp] parameter an | Aug 31, 2006 | 7.5 | 30 | NO | YES |
CVE-2004-0070HIGH PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a r | Feb 17, 2004 | 7.5 | 29 | NO | YES |
CVE-2008-2135HIGH Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.p | May 9, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-4478HIGH SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the groupname parameter. | Aug 31, 2006 | 7.5 | 28 | NO | YES |
CVE-2004-0132HIGH Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated us | Mar 3, 2004 | 7.5 | 28 | NO | YES |
CVE-2008-7054MEDIUM Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLanguage and (2) language_home pa | Aug 24, 2009 | 5.1 | 25 | NO | YES |
CVE-2008-7055MEDIUM module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot | Aug 24, 2009 | 5.1 | 23 | NO | YES |
CVE-2006-4479MEDIUM Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the subgroupname par | Aug 31, 2006 | 4.3 | 21 | NO | YES |
CVE-2003-1214HIGH Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted function | Feb 11, 2004 | 7.5 | 20 | NO | NO |
CVE-2002-1085HIGH Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities. | Oct 4, 2002 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Visualshapers.
Media articles that mention a CVE ID that affects a product developed by Visualshapers — matched by CVE ID, not by vendor name.