Xfairguy develops a small portfolio of web-based content and community platforms, including news and forum software products. The associated vulnerability disclosures cluster around general implementation issues reflected in the NVD classification system. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xfairguy over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1021HIGH SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter. | Feb 21, 2007 | 10.0 | 34 | NO | YES |
CVE-2006-2499HIGH SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field. | May 20, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-2822HIGH SQL injection vulnerability in admin/default.asp in Dusan Drobac CodeAvalanche FreeForum (aka CAForum) 1.0 allows remote attackers to execute arbitrary SQL commands via the passwor | Jun 5, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-2500MEDIUM Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to inject arbitrary web script or HTML via the Headline field. | May 20, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-2927MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in post.asp in CodeAvalanche FreeForum (aka CAForum) 1.0 allow remote attackers to inject arbitrary web script or HTML via the ( | Jun 9, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xfairguy.
Media articles that mention a CVE ID that affects a product developed by Xfairguy — matched by CVE ID, not by vendor name.