Factosystem maintains a narrowly scoped weblogging platform with a small, discrete vulnerability footprint. The observed exposures cluster around the platform's core application, with weakness classifications that align to general web application concerns. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Factosystem over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1499HIGH Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the | Apr 2, 2003 | 7.5 | 28 | NO | YES |
CVE-2008-5935MEDIUM Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a di | Jan 21, 2009 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Factosystem.
Media articles that mention a CVE ID that affects a product developed by Factosystem — matched by CVE ID, not by vendor name.