tramyardg CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

tramyardg vulnerability overview

Aggregates CVE and security vulnerability intelligence across all tramyardg-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact data exposure and vendor impact session compromise.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-30974 SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter. [email protected] 7.3 0.07% 2024-04-19 2025-09-23
CVE-2023-48903 Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php. [email protected] 6.1 0.19% 2024-03-21 2025-05-19
CVE-2023-48902 An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php. [email protected] 9.8 0.21% 2024-03-21 2025-05-19
CVE-2023-48901 A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php. [email protected] 9.8 0.70% 2024-03-21 2025-05-19
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence