Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Apache Friends

First CVE: Sep 26, 2006Active for: 20 yearsTotal CVEs: 16

Apache Friends maintains XAMPP, a widely used local development stack that bundles Apache, MySQL, PHP, and Perl to simplify web-application development across Windows, macOS, and Linux. The vendor's vulnerability footprint reflects the web-application composition of its integrated bundle, with observed weaknesses centering on cross-site scripting issues arising from improper input neutralization during web-page generation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 56% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 2% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Apache Friends over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 26, 2006
19 years ago
Most Recent CVE
Aug 30, 2025
328 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-10062HIGH
A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code.
Aug 30, 20258.744NOYES
CVE-2020-11107HIGH
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini fo
Apr 2, 20208.843NOYES
CVE-2019-8923CRITICAL
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
May 14, 20199.837NOYES
CVE-2024-0338CRITICAL
A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that contro
Feb 2, 20249.828NONO
CVE-2022-29376HIGH
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries l
May 23, 20228.828NONO
CVE-2019-8924MEDIUM
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
May 17, 20196.127NOYES
CVE-2017-20018HIGH
A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privil
Jun 9, 20227.826NONO
CVE-2008-6498MEDIUM
Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change
Mar 20, 20096.826NOYES
CVE-2008-3569MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the text par
Aug 10, 20084.326NOYES
CVE-2008-6499MEDIUM
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated
Mar 20, 20095.525NOYES
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
56%
31%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (12.5%)
Network7 (43.8%)
Unknown7 (43.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (56.3%)
High0 (0.0%)
Unknown7 (43.8%)
User Interaction
None5 (31.3%)
Unknown7 (43.8%)
Required4 (25.0%)
Privileges Required
Low2 (12.5%)
High1 (6.3%)
None6 (37.5%)
Unknown7 (43.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.2% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
43.8% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Apache Friends.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Apache Friends — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Apache Friends's Products

View all 4 CNAs →

Top CWEs