Website Seller Script Project maintains a narrowly scoped e-commerce application whose vulnerability profile centers on the Website Seller Script product and reflects characteristic web application input-handling weaknesses, including cross-site scripting, cross-site request forgery, path traversal, and buffer-boundary violations alongside broader input-validation gaps. These weakness classes are endemic to web-facing commerce platforms and recur across the product line, presenting a consistent attack surface for defenders to address through input sanitization, CSRF protections, and strict path constraints. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Website Seller Script Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11501HIGH PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS. | May 26, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-6879HIGH PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by | Apr 12, 2018 | 8.8 | 24 | NO | NO |
CVE-2018-15897MEDIUM PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, Company Name, or Fax fie | Aug 28, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-15896MEDIUM PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name. | Aug 28, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-6870MEDIUM Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature. | Apr 12, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-20631MEDIUM PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file. | Mar 21, 2019 | 5.3 | 19 | NO | NO |
CVE-2018-20530MEDIUM PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896. | Dec 28, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Website Seller Script Project.
Media articles that mention a CVE ID that affects a product developed by Website Seller Script Project — matched by CVE ID, not by vendor name.