Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Carmelogarcia

First CVE: Dec 10, 2023Active for: 3 yearsTotal CVEs: 27
43.3
VTI Score
High

Carmelogarcia maintains a narrow but diverse portfolio of web-based business applications spanning logistics, human resources, food service, and matrimonial services, each representing a distinct attack surface. Despite this focused product scope, the vendor's vulnerabilities skew strongly toward critical-severity outcomes, concentrated in foundational weakness classes such as SQL injection, cross-site scripting, code injection, and improper access control that are endemic to web application development. These recurring classes point to consistent input-validation and output-encoding gaps across the product line, reflecting vulnerabilities that are typically straightforward to exploit once discovered. Defenders should treat patches from this vendor as priority fixes for affected applications, particularly where they handle user input or access control; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
8.8
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Carmelogarcia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2023
2 years ago
Most Recent CVE
Dec 8, 2025
232 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-11553CRITICAL
A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-courier.php. Executing ma
Oct 9, 20259.833NONO
CVE-2025-13303CRITICAL
A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation
Nov 17, 20259.830NONO
CVE-2025-13302CRITICAL
A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument Mana
Nov 17, 20259.830NONO
CVE-2025-12316CRITICAL
A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argum
Oct 27, 20259.830NONO
CVE-2025-13396CRITICAL
A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument Offic
Nov 19, 20259.829NONO
CVE-2025-6124CRITICAL
A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipul
Jun 16, 20259.829NONO
CVE-2025-5980CRITICAL
A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affects unknown code of the file /order.php. The manipulation of t
Jun 10, 20259.829NONO
CVE-2024-10608CRITICAL
A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The mani
Nov 1, 20249.829NONO
CVE-2024-10607CRITICAL
A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. T
Nov 1, 20249.829NONO
CVE-2023-6651CRITICAL
A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unknown function of the file /auth/auth.php?user=1. The manipula
Dec 10, 20239.829NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
19%
19%
63%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.7%)
Network26 (96.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (81.5%)
Unknown0 (0.0%)
Required5 (18.5%)
Privileges Required
Low8 (29.6%)
High0 (0.0%)
None19 (70.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Carmelogarcia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Carmelogarcia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Carmelogarcia's Products

View all 2 CNAs →

Top CWEs