Vscripts maintains a narrowly scoped portfolio centered on web content management and publishing applications such as Vbook and Vnews, which occupy a modest but established niche in the vulnerability landscape. The vendor's disclosures frequently acquire public exploit tooling, making patching and inventory management important for defenders deploying these products. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vscripts over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1543HIGH Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) ad | Mar 30, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-1545HIGH Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting t | Mar 30, 2006 | 9.0 | 23 | NO | NO |
CVE-2006-1563HIGH Direct static code injection vulnerability in config.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote administrators to execute arbitrary PHP code into t | Mar 31, 2006 | 7.6 | 20 | NO | NO |
CVE-2006-1562MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allow remote attackers to inject arbitrary web script or | Mar 31, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-1561MEDIUM SQL injection vulnerability in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote attackers to execute arbitrary SQL commands via the x parameter. | Mar 31, 2006 | 5.1 | 15 | NO | NO |
CVE-2006-1544MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1 | Mar 30, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vscripts.
Media articles that mention a CVE ID that affects a product developed by Vscripts — matched by CVE ID, not by vendor name.