Freereprintables maintains a narrowly scoped web application portfolio centered on the ArticleFR product, where vulnerabilities skew toward serious outcomes and have a strong tendency to acquire public exploit tooling. The recurring weakness classes—cross-site scripting, SQL injection, cross-site request forgery, path traversal, and improper privilege management—reflect typical application-layer input-handling and access-control gaps in web platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freereprintables over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4170CRITICAL A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malic | Feb 13, 2020 | 9.8 | 41 | NO | YES |
CVE-2015-1364HIGH SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL command | Jan 27, 2015 | 7.5 | 34 | NO | YES |
CVE-2014-5097HIGH Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get o | Aug 22, 2014 | 7.5 | 34 | NO | YES |
CVE-2015-5530MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to hijack the authentication of administrators for requests t | Jul 16, 2015 | 6.8 | 30 | NO | YES |
CVE-2015-5529MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to | Jul 16, 2015 | 4.3 | 22 | NO | YES |
CVE-2015-6591MEDIUM Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s p | Jan 15, 2020 | 5.5 | 16 | NO | NO |
CVE-2015-1363MEDIUM Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter to search/v/. | Jan 27, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freereprintables.
Media articles that mention a CVE ID that affects a product developed by Freereprintables — matched by CVE ID, not by vendor name.