Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dasinfomedia

First CVE: Sep 28, 2017Active for: 9 yearsTotal CVEs: 15
44.9
VTI Score
High

Dasinfomedia develops a focused line of institutional management software spanning school administration, hospital operations, apartment facilities, and SMS gateway systems. The vulnerability profile centers on recurrent web-application and access-control weaknesses—SQL injection, unrestricted file upload, missing authorization, and authentication bypass—that are endemic to rapidly developed administrative platforms with legacy codebases. Public exploit code availability tends to be elevated for this vendor's disclosures, reflecting the appeal of these accessible management interfaces to opportunistic attackers; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dasinfomedia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 28, 2017
8 years ago
Most Recent CVE
Mar 7, 2025
504 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-14847HIGH
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
Sep 28, 20178.839NOYES
CVE-2017-14848HIGH
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
Oct 3, 20178.837NOYES
CVE-2017-14846HIGH
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
Sep 28, 20178.837NOYES
CVE-2017-14845HIGH
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
Sep 28, 20178.837NOYES
CVE-2017-14844HIGH
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
Sep 28, 20178.837NOYES
CVE-2017-14843HIGH
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
Sep 28, 20178.837NOYES
CVE-2017-14842HIGH
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
Sep 28, 20178.837NOYES
CVE-2017-14841MEDIUM
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
Sep 28, 20176.531NOYES
CVE-2024-9659CRITICAL
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload(
Nov 23, 20249.827NONO
CVE-2024-9658HIGH
The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due
Mar 7, 20258.825NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
33%
60%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low12 (80.0%)
High0 (0.0%)
None3 (20.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
53.3% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dasinfomedia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dasinfomedia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dasinfomedia's Products

View all 2 CNAs →

Top CWEs