Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Alf

First CVE: Apr 24, 2023Active for: 3 yearsTotal CVEs: 9

Alf is a modestly represented vendor with a narrowly scoped product footprint concentrated in a single core application. The recurring vulnerability signal reflects access-control and information-handling issues—including authorization bypass, race conditions, and sensitive-data exposure—alongside a class of disclosures tagged as generic placeholders by NVD, which limits structural clarity on the underlying weakness patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Alf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2023
3 years ago
Most Recent CVE
Sep 6, 2024
686 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2258HIGH
Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
Apr 24, 20238.828NONO
CVE-2023-2260HIGH
Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
Apr 24, 20238.827NONO
CVE-2024-25635HIGH
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization owners using th
Feb 19, 20248.824NONO
CVE-2024-25628HIGH
Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This iss
Feb 16, 20247.621NONO
CVE-2024-45299MEDIUM
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctl
Sep 6, 20246.519NONO
CVE-2023-2259HIGH
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
Apr 24, 20237.219NONO
CVE-2024-25634MEDIUM
alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a specially crafted reques
Feb 19, 20246.517NONO
CVE-2024-45300MEDIUM
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user to bypass the lim
Sep 6, 20245.916NONO
CVE-2024-25627MEDIUM
Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able to upload HTML files that trigger JavaScript payloads. As su
Feb 16, 20244.816NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
56%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low4 (44.4%)
High3 (33.3%)
None2 (22.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Alf.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Alf — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Alf's Products

View all 2 CNAs →

Top CWEs