Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Etoilewebdesign

First CVE: Aug 2, 2017Active for: 9 yearsTotal CVEs: 26
33.7
VTI Score
Medium

Etoilewebdesign maintains a focused portfolio of web-based e-commerce and content-management plugins and modules, including products such as Ultimate FAQ, Ultimate Product Catalog, and Order Tracking that are embedded across small-to-medium business websites. Despite a narrow product range, this vendor appears prominently in the vulnerability landscape, with disclosures skewing toward critical-severity outcomes and frequently acquiring public exploit code. The recurring weakness classes center on web-application fundamentals: cross-site scripting, SQL injection, missing authorization, cross-site request forgery, and untrusted deserialization—flaws typical of server-side plugins that handle user input and manage access control with minimal isolation. Defenders deploying these plugins should treat security updates as high-priority and audit authentication and input-handling configurations; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Etoilewebdesign over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2017
8 years ago
Most Recent CVE
May 15, 2025
435 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-2005CRITICAL
The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versi
Apr 2, 20259.842NONO
CVE-2019-17232HIGH
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
Oct 7, 20197.535NOYES
CVE-2024-13569HIGH
The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting whic
Apr 22, 20257.130NOYES
CVE-2019-17233MEDIUM
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
Oct 7, 20196.130NOYES
CVE-2025-47580CRITICAL
Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fr
May 15, 20259.829NONO
CVE-2020-36726CRITICAL
The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerabl
Jun 7, 20239.827NONO
CVE-2024-7607HIGH
The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 3.2.28 due to insufficient escapi
Aug 29, 20248.825NONO
CVE-2020-7107MEDIUM
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
Jan 16, 20206.125NOYES
CVE-2023-34005HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Front End Users plugin <= 3.2.24 versions.
Jul 17, 20238.824NONO
CVE-2017-12199CRITICAL
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_or
Aug 2, 20179.824NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
65%
19%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (34.6%)
Unknown0 (0.0%)
Required17 (65.4%)
Privileges Required
Low7 (26.9%)
High4 (15.4%)
None15 (57.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
15.4% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Etoilewebdesign.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Etoilewebdesign — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Etoilewebdesign's Products

View all 4 CNAs →

Top CWEs