Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yourfreeworld

First CVE: May 22, 2006Active for: 20 yearsTotal CVEs: 30
49.5
VTI Score
High

Yourfreeworld distributes a collection of web-application scripts and widgets oriented toward classified listings, URL shortening, text styling, and rating functionality, representing a portfolio of widely embedded applications with substantial reach across small-business and community websites. The vendor's vulnerability exposure concentrates on application-layer input handling, with SQL injection and cross-site scripting forming the durable signal across its product line—weaknesses endemic to web-facing script deployment where input sanitization and output encoding are critical. A notable and distinguishing characteristic of this vendor's disclosures is their strong tendency to attract public exploit code development, reflecting the accessibility of these script products to security researchers and the appeal of web-application vulnerabilities for proof-of-concept tooling. Defenders running any of these scripts should treat patch deployment as a priority for internet-facing services and implement robust input validation and context-appropriate output encoding as compensating controls. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yourfreeworld over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2006
20 years ago
Most Recent CVE
Nov 1, 2011
5,379 days ago

Products(22 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-4884HIGH
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Nov 4, 20087.531NOYES
CVE-2010-4981HIGH
SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these
Nov 1, 20117.530NOYES
CVE-2008-1919HIGH
SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the r parameter.
Apr 23, 20087.530NOYES
CVE-2008-4900HIGH
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Nov 4, 20087.529NOYES
CVE-2008-4881HIGH
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Nov 4, 20087.529NOYES
CVE-2008-4895HIGH
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL commands via the id parameter.
Nov 4, 20087.528NOYES
CVE-2008-4886HIGH
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.
Nov 4, 20087.528NOYES
CVE-2008-4885HIGH
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Nov 4, 20087.528NOYES
CVE-2008-4883HIGH
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Nov 4, 20087.528NOYES
CVE-2008-4882HIGH
SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Nov 4, 20087.528NOYES
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
23%
77%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown30 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown30 (100.0%)
User Interaction
None0 (0.0%)
Unknown30 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown30 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
21 CVEs
70.0% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yourfreeworld.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yourfreeworld — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yourfreeworld's Products

View all 1 CNAs →

Top CWEs