VYPR
Vendor

Inout

Products
9
CVEs
15
Across products
20
Status
Private

Products

9

Recent CVEs

15
  • CVE-2019-25640HigMar 24, 2026
    risk 0.53cvss 8.2epss 0.00

    Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive…

  • CVE-2019-25528HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the property1 parameter. Attackers can send POST requests to the search/searchdetailed endpoint with…

  • CVE-2019-25527HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the numguest parameter. Attackers can send POST requests to the search/searchdetailed endpoint with…

  • CVE-2019-25526HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the location parameter. Attackers can send POST requests to the search/searchdetailed endpoint with…

  • CVE-2019-25525HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the guests parameter. Attackers can send POST requests to the search/rentals endpoint with malicious…

  • CVE-2022-32055HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=search/rentals.

  • CVE-2022-31489HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.

  • CVE-2022-31488HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.

  • CVE-2022-31487HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.

  • CVE-2022-34988MedJul 26, 2022
    risk 0.35cvss 5.4epss 0.01

    Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js.

  • CVE-2007-2988Jun 1, 2007
    risk 0.04cvss —epss 0.08

    A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a…

  • CVE-2009-3223Sep 16, 2009
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-2002Apr 12, 2007
    risk 0.03cvss —epss 0.02

    InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by setting an arbitrary admin cookie.

  • CVE-2007-2003Apr 12, 2007
    risk 0.03cvss —epss 0.02

    InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.

  • CVE-2007-2004Apr 12, 2007
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to changename.php and other unspecified vectors.