Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hotcrp

First CVE: Dec 28, 2022Active for: 4 yearsTotal CVEs: 4

Hotcrp is a specialized conference-management platform used in academic peer-review workflows, with vulnerabilities centered on the single product and rooted in web-application input handling. The durable signal reflects cross-site scripting, improper input validation, and data-exposure issues typical of web-facing administrative systems; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hotcrp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2022
3 years ago
Most Recent CVE
Jan 30, 2026
175 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-23836HIGH
HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to tri
Jan 19, 20268.830NONO
CVE-2026-25156MEDIUM
HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all types with inline Content-Disposition, causing them to be re
Jan 30, 20266.322NONO
CVE-2026-23878MEDIUM
HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02c984b4a0, authors with at leas
Jan 19, 20266.522NONO
CVE-2022-4819MEDIUM
A vulnerability was found in HotCRP. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The att
Dec 28, 20226.118NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
75%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (50.0%)
Unknown0 (0.0%)
Required2 (50.0%)
Privileges Required
Low3 (75.0%)
High0 (0.0%)
None1 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hotcrp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hotcrp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hotcrp's Products

View all 2 CNAs →

Top CWEs