Facetag Project maintains a focused web application platform where the observed vulnerability surface centers on input-handling weaknesses, specifically cross-site scripting and SQL injection flaws in the core Facetag product. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Facetag Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9426CRITICAL ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action. | Feb 26, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-9425MEDIUM The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action. | Feb 26, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Facetag Project.
Media articles that mention a CVE ID that affects a product developed by Facetag Project — matched by CVE ID, not by vendor name.