Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Flyspray

First CVE: Oct 27, 2005Active for: 21 yearsTotal CVEs: 10
28.8
VTI Score
Low

Flyspray is a lightweight, open-source issue-tracking and project-management application with a modestly represented vulnerability footprint concentrated in a single product line. Its disclosures recur through web-application input-handling and session-management weakness classes, including cross-site scripting, cross-site request forgery, and sensitive-information exposure, which reflect the attack surface inherent to publicly exposed tracking and collaboration tools; the vendor's vulnerabilities frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.3
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Flyspray over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 27, 2005
20 years ago
Most Recent CVE
Oct 11, 2017
3,208 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1058MEDIUM
Cross-site request forgery (CSRF) vulnerability in Flyspray 0.9.9.6 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an admin
Feb 14, 20126.029NOYES
CVE-2006-0714MEDIUM
Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence
Feb 15, 20065.025NOYES
CVE-2005-3334MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID,
Oct 27, 20054.322NOYES
CVE-2007-1789MEDIUM
Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.
Mar 31, 20076.820NONO
CVE-2017-15213MEDIUM
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to
Oct 11, 20175.419NONO
CVE-2017-15214MEDIUM
Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges and also to execute JavaScript agains
Oct 11, 20175.418NONO
CVE-2007-1788MEDIUM
Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted post request.
Mar 31, 20076.818NONO
CVE-2008-1166MEDIUM
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
Mar 5, 20085.017NONO
CVE-2008-1165MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script or HTML via (1) a forced SQL error messa
Mar 5, 20084.314NONO
CVE-2007-6461MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flyspray 0.9.9 through 0.9.9.3 allow remote attackers to inject arbitrary web script or HTML via (1) the query s
Dec 20, 20074.314NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network2 (20.0%)
Unknown8 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (20.0%)
High0 (0.0%)
Unknown8 (80.0%)
User Interaction
None0 (0.0%)
Unknown8 (80.0%)
Required2 (20.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (80.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
30.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Flyspray.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Flyspray — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Flyspray's Products

View all 1 CNAs →

Top CWEs