Facilemanager is a network administration and management platform that exhibits a narrow vulnerability footprint concentrated in web-application input handling, with recurring exposure to cross-site scripting, SQL injection, and authorization weaknesses. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Facilemanager over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24573HIGH facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POST request containing user infor | Jan 31, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-30918MEDIUM facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and | Mar 10, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-30919MEDIUM facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application | Mar 10, 2026 | 5.4 | 21 | NO | NO |
CVE-2024-24572MEDIUM facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() func | Jan 31, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-24571MEDIUM facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present i | Jan 31, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Facilemanager.
Media articles that mention a CVE ID that affects a product developed by Facilemanager — matched by CVE ID, not by vendor name.