CVE Tools

Jelsoft

53 CVEs tracked since 2001. Since Sep 2001, none of them reached CISA KEV.

Jelsoft CVEs per month

Sep 2001 to Oct 2007. Point at a month, or focus the strip and use the arrow keys.
Jelsoft CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2001-0910
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-03null or fewer
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-0510
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-0110
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-0610
2004-07null or fewer
2004-08null or fewer
2004-0910
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-0230
2005-03null or fewer
2005-04null or fewer
2005-0530
2005-0630
2005-07null or fewer
2005-0810
2005-0970
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-0120
2006-02null or fewer
2006-0320
2006-0430
2006-05null or fewer
2006-0620
2006-07null or fewer
2006-0830
2006-09null or fewer
2006-1010
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-0220
2007-0330
2007-04null or fewer
2007-0550
2007-0630
2007-07null or fewer
2007-0820
2007-0910
2007-1020

Products

The products that kept showing up in Jelsoft's monthly top three, with their CVEs summed over those months.

  1. Vbulletin4822 months
  2. Vbsupport Integrated Ticket System21 month
  3. Impex11 month
  4. Oscmax11 month
  5. Vbug Tracker11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Jelsoft.

  1. CVE-2002-2235member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which f...5.0
  2. CVE-2004-2695SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via t...7.5
  3. CVE-2007-4959Cross-site scripting (XSS) vulnerability in catalog_products_with_images.php in osCMax 2.0.0-RC3-0-1 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenanc...4.3
  4. CVE-2007-4453Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.8 allow remote attackers to inject arbitrary web code or HTML via the (1) s parameter to index.php, and the (2) q parameter to (...4.3
  5. CVE-2007-4120Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) classfile parameter to includes/functions.php...9.3
  6. CVE-2007-3326Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php...5.8
  7. CVE-2007-3197SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unspecified vectors.7.5
  8. CVE-2007-3196SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.7.5
  9. CVE-2007-2912Unspecified vulnerability in Jelsoft vBulletin before 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote attackers to see the infraction "red flag" for a deleted user.5.0
  10. CVE-2007-2911SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (...8.5
  11. CVE-2007-2908Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action.4.3
  12. CVE-2007-2910Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.6.7 PL1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_367_xss_fix_...4.3
  13. CVE-2007-2909Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to t...3.5
  14. CVE-2007-1573SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field.6.0
  15. CVE-2007-1342Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form.4.3

The record

Peak rank
#4 in Sep 2005
Busiest month shown
Sep 2005, 7 CVEs
Months with a KEV entry
0 since Sep 2001
Monthly snapshots
23 since 2001
Jelsoft's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store