Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Devcode

First CVE: Sep 11, 2023Active for: 3 yearsTotal CVEs: 17
40.9
VTI Score
High

Devcode's vulnerability profile centers on OpenStaManager, a modestly represented business management and invoicing application that recurs with a meaningful share of serious-severity disclosures. The durable weakness classes affecting the product span web application input handling and authentication boundaries, including SQL injection, cross-site scripting, OS command injection, unsafe deserialization, and missing authentication controls—patterns typical of server-side PHP applications with evolving security maturity. Defenders deploying this application should prioritize patching for injection and authentication classes and restrict network exposure; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
8.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Devcode over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2023
2 years ago
Most Recent CVE
May 4, 2026
81 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-27012CRITICAL
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in
Mar 3, 20269.832NONO
CVE-2026-35470HIGH
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager c
Apr 6, 20268.830NONO
CVE-2026-35168HIGH
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains
Apr 2, 20268.830NONO
CVE-2026-28805HIGH
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable
Apr 2, 20268.830NONO
CVE-2025-69212HIGH
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerability exists in the P7M (
Feb 6, 20268.829NONO
CVE-2026-38751HIGH
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
May 4, 20267.228NONO
CVE-2025-69214HIGH
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the ajax_select.php endp
Feb 6, 20268.827NONO
CVE-2025-69213HIGH
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists in the ajax_complete.p
Feb 4, 20268.827NONO
CVE-2025-69215HIGH
OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability in the Stampe Module
Feb 4, 20268.825NONO
CVE-2026-29782HIGH
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated en
Apr 2, 20267.224NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
41%
53%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (88.2%)
Unknown0 (0.0%)
Required2 (11.8%)
Privileges Required
Low12 (70.6%)
High2 (11.8%)
None3 (17.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Devcode.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Devcode — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Devcode's Products

View all 2 CNAs →

Top CWEs