Xtreme Scripts operates a small portfolio of web-based applications, including its TopSites ranking system and Download Manager, where the recurring vulnerability signal centers on improper input handling and cross-site scripting weaknesses. These are typical application-layer injection issues that arise in web-facing script products handling user-supplied data and dynamic page generation. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xtreme Scripts over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2964HIGH Multiple PHP remote file inclusion vulnerabilities in Xtreme Scripts Download Manager (aka Xtreme Downloads) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in t | Jun 12, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-2543MEDIUM Xtreme Topsites 1.1 allows remote attackers to trigger MySQL errors and possibly conduct SQL injection attacks via unspecified vectors in join.php. | May 23, 2006 | 5.1 | 15 | NO | NO |
CVE-2006-2544MEDIUM Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis param | May 23, 2006 | 5.1 | 15 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in stats.php and ( | May 23, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xtreme Scripts.
Media articles that mention a CVE ID that affects a product developed by Xtreme Scripts — matched by CVE ID, not by vendor name.