Nextclickventures Vulnerabilities
Comprehensive security vulnerability database for Nextclickventures products
9
0
8
9
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2015-20121 | 8.8 | This vulnerability allows attackers to manipulate database queries and potentially access sensitive information by injecting malicious SQL code through specific web form inputs, without needing to log in. All an attacker needs is to send specially crafted requests to the affected URLs, making it relatively easy to exploit. | nextclickventuresrealtyscript | Exploit Available | 22 days agoMar 16, 2026 |
| CVE-2015-20120 | 8.8 | This vulnerability allows attackers to secretly access and extract sensitive information from the database of RealtyScript by sending specially crafted requests, even without logging in. They can do this by measuring how long it takes the system to respond, which reveals data one piece at a time. | nextclickventuresrealtyscript | Exploit Available | 22 days agoMar 16, 2026 |
| CVE-2015-20119 | 5.1 | This vulnerability allows an attacker with a valid account to inject harmful HTML and iframe code into the RealtyScript admin interface, which can then execute in the browsers of users who visit affected pages. To exploit this, the attacker must submit a specially crafted request while logged in, enabling them to store and display malicious content to other users. | nextclickventuresrealtyscript | Exploit Available | 22 days agoMar 16, 2026 |
| CVE-2015-20118 | 5.1 | This vulnerability allows an attacker to run malicious JavaScript code in the browsers of administrators by submitting specially crafted data through the admin locations interface. To exploit this, the attacker needs access to the locations.php endpoint and must input harmful scripts into the location_name field. | nextclickventuresrealtyscript | Exploit Available | 22 days agoMar 16, 2026 |
| CVE-2015-20117 | 6.9 | This vulnerability allows attackers to create unauthorized user accounts, including administrative ones, by tricking users into submitting malicious forms. It requires no authentication, meaning anyone can exploit it simply by sending specially crafted requests to the system's user management endpoints. | nextclickventuresrealtyscript | Exploit Available | 22 days agoMar 16, 2026 |
| CVE-2015-20116 | 5.1 | This vulnerability allows attackers to upload files with malicious scripts hidden in the filenames, which can then run harmful JavaScript in users' browsers when the files are viewed. It occurs because the system does not properly check or clean the filenames in the uploaded files, making it easy for attackers to exploit this weakness. | nextclickventuresrealtyscript | Exploit Available | 22 days agoMar 16, 2026 |
| CVE-2015-20115 | 5.1 | This vulnerability allows attackers to upload harmful JavaScript files to the RealtyScript application, which can then run when other users access the affected admin page. To exploit this, the attacker needs access to the file upload feature in the admin tools section of the application. | nextclickventuresrealtyscript | Exploit Available | 22 days agoMar 16, 2026 |
| CVE-2015-20114 | 5.1 | This vulnerability allows attackers to run harmful scripts in users' web browsers when they interact with the affected RealtyScript application. It occurs because the application fails to properly clean user input, enabling attackers to send specially crafted requests that include their malicious code. | nextclickventuresrealtyscript | Exploit Available | 22 days agoMar 16, 2026 |
| CVE-2015-20113 | 6.9 | This vulnerability allows attackers to perform unauthorized actions as an administrator and inject harmful scripts into the RealtyScript application. It requires the attacker to trick logged-in users into visiting a malicious web page or to exploit the application to store and execute their scripts. | nextclickventuresrealtyscript | Theoretical | 22 days agoMar 16, 2026 |
About Nextclickventures Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Nextclickventures products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.