Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fairsketch

First CVE: Jul 12, 2017Active for: 9 yearsTotal CVEs: 16
39.5
VTI Score
Medium

Fairsketch's vulnerability footprint centers on its Rise Ultimate Project Manager product, a web-based project-management application where the disclosure pattern reflects application-layer input-handling and access-control weaknesses. The recurring weakness classes—cross-site scripting, SQL injection, cross-site request forgery, resource injection, and missing authorization—are characteristic of web applications handling user input and session state, and the vendor's disclosures tend to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fairsketch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2017
9 years ago
Most Recent CVE
Nov 11, 2025
255 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-8945HIGH
A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboar
Sep 17, 20248.843NOYES
CVE-2017-17999CRITICAL
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_
Jan 23, 20189.842NOYES
CVE-2025-60378HIGH
Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDF
Oct 10, 20258.129NONO
CVE-2025-63293MEDIUM
FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for whi
Nov 3, 20256.525NONO
CVE-2019-18884HIGH
index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
Nov 13, 20198.825NONO
CVE-2025-56807MEDIUM
A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in
Sep 29, 20256.123NONO
CVE-2025-41102MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a P
Nov 11, 20255.420NONO
CVE-2017-11182MEDIUM
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable.
Jul 12, 20175.420NONO
CVE-2025-41106MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a P
Nov 11, 20255.419NONO
CVE-2025-41105MEDIUM
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a P
Nov 11, 20255.419NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
75%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (31.3%)
Unknown0 (0.0%)
Required11 (68.8%)
Privileges Required
Low12 (75.0%)
High0 (0.0%)
None4 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fairsketch.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fairsketch — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fairsketch's Products

View all 3 CNAs →

Top CWEs