Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Carmelo

First CVE: Feb 22, 2024Active for: 2 yearsTotal CVEs: 127
44.5
VTI Score
High

Carmelo maintains a portfolio of web-based ordering, management, and community-engagement applications including pizza ordering systems, donation platforms, membership management, and event judging tools. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate across a consistent set of input-handling and code-execution weakness classes: SQL injection, cross-site scripting, injection flaws, code injection, and unrestricted file uploads are the dominant exposure patterns. These are structural weaknesses endemic to web applications that process user input without adequate sanitization and validation, reflecting a pattern of unsafe handling at multiple layers—from database queries to output generation to file acceptance. Defenders should treat updates for this vendor's products as high-priority when these systems face internet or untrusted-network exposure, particularly where they manage sensitive data or control operational workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
127
Total CVEs
More Total CVEs than 99% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Carmelo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2024
2 years ago
Most Recent CVE
Mar 29, 2026
117 days ago

Products(26 total)

Top CVEs

Signals from CVEs in this vendor scope (127 CVEs).

127 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-60307CRITICAL
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempt
Oct 10, 20259.837NONO
CVE-2026-0700CRITICAL
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a mani
Jan 8, 20269.834NONO
CVE-2025-15011CRITICAL
A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.php. The manipulation of the argument uname results in sql i
Dec 22, 20259.834NONO
CVE-2025-14647CRITICAL
A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn c
Dec 14, 20259.834NONO
CVE-2025-14223CRITICAL
A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /request.php. Such manipulation of
Dec 8, 20259.834NONO
CVE-2025-13323CRITICAL
A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Performing manipulation of the ar
Nov 18, 20259.834NONO
CVE-2025-11556CRITICAL
A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /user.php. This manipulation of the argument table causes sql i
Oct 9, 20259.834NONO
CVE-2025-10103CRITICAL
A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /home.php. Executing manipulation of the argument main
Sep 8, 20259.834NONO
CVE-2025-8493CRITICAL
A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_q
Aug 2, 20259.834NONO
CVE-2026-5019CRITICAL
A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of t
Mar 29, 20269.832NONO
View all 127 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products127 CVEs
11%
28%
61%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (1.6%)
Network125 (98.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low127 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None115 (90.6%)
Unknown0 (0.0%)
Required12 (9.4%)
Privileges Required
Low30 (23.6%)
High13 (10.2%)
None84 (66.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (127 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Carmelo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Carmelo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Carmelo's Products

View all 2 CNAs →

Top CWEs