Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Egavilanmedia

First CVE: Dec 15, 2020Active for: 6 yearsTotal CVEs: 14
32.2
VTI Score
Medium

Egavilanmedia's vulnerability profile centers on a modest portfolio of web-based business applications including user registration, expense management, and address-book systems that serve administrative and operational functions. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through application-layer input-handling weaknesses: SQL injection, cross-site scripting, and cross-site request forgery are characteristic of web applications with insufficient input validation and output encoding. Defenders should prioritize patches for this vendor's administrative and data-facing products and apply defense-in-depth validation controls; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Egavilanmedia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2020
5 years ago
Most Recent CVE
Jun 2, 2022
1,515 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35276CRITICAL
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
Dec 21, 20209.833NONO
CVE-2021-44096CRITICAL
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise
Jun 2, 20229.831NONO
CVE-2021-44098CRITICAL
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.
Jun 2, 20229.830NONO
CVE-2020-29474CRITICAL
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrar
Dec 24, 20209.830NONO
CVE-2020-29472CRITICAL
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perf
Dec 24, 20209.830NONO
CVE-2020-35263CRITICAL
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
Jan 26, 20219.828NONO
CVE-2020-35273HIGH
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attac
Dec 21, 20208.026NONO
CVE-2020-29228HIGH
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
Dec 30, 20207.521NONO
CVE-2020-29231MEDIUM
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the atta
Dec 30, 20205.420NONO
CVE-2020-35252MEDIUM
Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.
Dec 23, 20206.120NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
43%
14%
43%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (50.0%)
Unknown0 (0.0%)
Required7 (50.0%)
Privileges Required
Low3 (21.4%)
High0 (0.0%)
None11 (78.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Egavilanmedia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Egavilanmedia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Egavilanmedia's Products

View all 1 CNAs →

Top CWEs