Jettweb Vulnerabilities
Comprehensive security vulnerability database for Jettweb products
14
0
9
14
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2019-25520 | 8.8 | This vulnerability allows attackers to gain full administrative access to the PHP stock news site script without needing a valid username or password. They can exploit this by entering specially crafted input in the login form, which tricks the system into bypassing security checks. | jettwebphp stock news site script | Theoretical | 26 days agoMar 12, 2026 |
| CVE-2019-25519 | 8.8 | This vulnerability allows attackers to manipulate database queries and extract sensitive information by sending specially crafted requests to a specific page in the Jettweb PHP stock news site script. It requires the attacker to send POST requests with malicious input in a certain parameter, making it possible to execute harmful SQL commands. | jettwebphp stock news site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25518 | 8.8 | This vulnerability allows attackers to send specially crafted requests to a specific page of the Jettweb PHP script, enabling them to access or change sensitive information in the database without needing to log in. The only requirement is that they must be able to send a POST request with malicious code in a specific parameter. | jettwebphp stock news site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25517 | 8.8 | This vulnerability allows attackers to access or change sensitive information in the database by sending specially crafted requests to the script without needing to log in. They can exploit this flaw by manipulating a specific part of the URL, which lets them run harmful SQL commands. | jettwebphp stock news site script | Theoretical | 26 days agoMar 12, 2026 |
| CVE-2019-25516 | 8.8 | This vulnerability allows attackers to access sensitive information from the database by sending specially crafted requests to the website, specifically through a parameter called gallery_id. The attacker does not need to log in or have any special permissions, making it easy for anyone to exploit this flaw. | jettwebphp stock news site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25515 | 8.7 | This vulnerability allows attackers to gain unauthorized access to the administration panel of a PHP stock news site script without needing valid login credentials. They can exploit this by entering specific SQL commands in the username and password fields, making it easy for anyone to take control if they know how to craft the right input. | jettwebphp stock news site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25514 | 8.8 | This vulnerability allows attackers to send harmful SQL commands through a specific input field in the PHP stock news site script, enabling them to steal sensitive data or bypass login protections. To exploit this, the attacker needs to send a specially crafted POST request with malicious input. | jettwebphp stock news site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25513 | 8.8 | This vulnerability allows attackers to manipulate database queries and potentially access sensitive information by sending specially crafted requests to the script without needing to log in. They can exploit this weakness by using specific input in the 'q' parameter, making it a serious risk for any site using this script. | jettwebphp stock news site script | Theoretical | 26 days agoMar 12, 2026 |
| CVE-2019-25512 | 8.8 | This vulnerability allows attackers to inject harmful SQL commands into the database through a specific input field in POST requests, enabling them to steal sensitive information or alter data. To exploit this, the attacker needs to send a specially crafted request that targets the vulnerable script. | jettwebphp stock news site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25511 | 8.8 | This vulnerability allows attackers to access and extract sensitive information from the database by sending specially crafted requests to a specific script without needing to log in. They can do this by manipulating a parameter in the URL, making it easy for them to steal data if the site is not properly secured. | jettwebphp stock news site script | Theoretical | 26 days agoMar 12, 2026 |
| CVE-2019-25510 | 8.8 | This vulnerability allows attackers to gain unauthorized access to the administration panel of a PHP stock news site script without needing valid login credentials. By exploiting weaknesses in how the script handles login information, attackers can use specially crafted input to bypass security and control the site. | jettwebphp stock news site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25508 | 8.8 | This vulnerability allows attackers to access sensitive information from the database by sending specially crafted requests to a specific endpoint, without needing to log in. They can exploit this flaw by manipulating a parameter in the URL, making it possible to retrieve data that should be protected. | jettwebphp ready advertisement site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25488 | 8.8 | This vulnerability allows attackers to access and manipulate the database of the php ready rent a car site without needing to log in, simply by sending specially crafted requests to the admin panel. By exploiting this flaw, they can extract sensitive information or potentially disrupt the service. | jettwebphp ready rent a car site script | Exploit Available | 26 days agoMar 12, 2026 |
| CVE-2019-25482 | 8.8 | This vulnerability allows attackers to access and manipulate the database of the PHP car rental script without needing to log in, simply by sending specially crafted requests with harmful SQL code. As a result, they can extract sensitive information from the database, posing a significant risk to the site's security. | jettwebphp ready rent a car site script | Theoretical | 26 days agoMar 12, 2026 |
About Jettweb Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Jettweb products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.