Yourfreeworld distributes a collection of web-application scripts and widgets oriented toward classified listings, URL shortening, text styling, and rating functionality, representing a portfolio of widely embedded applications with substantial reach across small-business and community websites. The vendor's vulnerability exposure concentrates on application-layer input handling, with SQL injection and cross-site scripting forming the durable signal across its product line—weaknesses endemic to web-facing script deployment where input sanitization and output encoding are critical. A notable and distinguishing characteristic of this vendor's disclosures is their strong tendency to attract public exploit code development, reflecting the accessibility of these script products to security researchers and the appeal of web-application vulnerabilities for proof-of-concept tooling. Defenders running any of these scripts should treat patch deployment as a priority for internet-facing services and implement robust input validation and context-appropriate output encoding as compensating controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yourfreeworld over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4884HIGH SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 4, 2008 | 7.5 | 31 | NO | YES |
CVE-2010-4981HIGH SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these | Nov 1, 2011 | 7.5 | 30 | NO | YES |
CVE-2008-1919HIGH SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the r parameter. | Apr 23, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-4900HIGH SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 4, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-4881HIGH SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 4, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-4895HIGH SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 4, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4886HIGH SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter. | Nov 4, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4885HIGH SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 4, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4883HIGH SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 4, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4882HIGH SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 4, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yourfreeworld.
Media articles that mention a CVE ID that affects a product developed by Yourfreeworld — matched by CVE ID, not by vendor name.