Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ecisp

First CVE: Aug 24, 2021Active for: 5 yearsTotal CVEs: 7

Ecisp develops a focused content-management system product line, primarily the ESPCMS family, that serves as a web-publishing platform with a relatively small but persistent vulnerability footprint. The system's exposure recurs through classic web-application weaknesses—SQL injection, cross-site scripting, and code injection—that reflect the challenges of user-input handling and templating in CMS platforms, and a meaningful share of the vendor's disclosures reach critical severity. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ecisp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2021
4 years ago
Most Recent CVE
Jun 27, 2023
1,123 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-44088CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
Nov 10, 20229.836NONO
CVE-2022-44087CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
Nov 10, 20229.834NONO
CVE-2022-44089CRITICAL
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
Nov 10, 20229.833NONO
CVE-2020-18913HIGH
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers
Aug 24, 20217.525NONO
CVE-2022-33085HIGH
ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates.
Jun 30, 20227.224NONO
CVE-2023-23007HIGH
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.
Feb 17, 20237.223NONO
CVE-2020-18404MEDIUM
An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter.
Jun 27, 20234.817NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
43%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low0 (0.0%)
High3 (42.9%)
None4 (57.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ecisp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ecisp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ecisp's Products

View all 1 CNAs →

Top CWEs