Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lopalopa

First CVE: Jan 8, 2024Active for: 3 yearsTotal CVEs: 112
31.9
VTI Score
Medium

Lopalopa develops a narrow suite of educational and institutional management systems—including e-learning platforms, music management tools, and school administration software—that serve a modest number of discrete products but maintain prominence in their targeted verticals. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur consistently across its product line through application-layer input-handling weaknesses: SQL injection, cross-site scripting, and improper access control are the dominant patterns. These flaws are characteristic of web-based administrative and educational software where user input handling and privilege boundaries require careful design, and their presence across multiple management systems underscores a durable structural exposure in this vendor's codebase. Defenders deploying Lopalopa systems should prioritize input-validation and access-control review during security assessments and apply patches promptly given the severity tendency. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
112
Total CVEs
More Total CVEs than 99% of tracked vendors
7.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lopalopa over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 8, 2024
2 years ago
Most Recent CVE
May 27, 2025
423 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (112 CVEs).

112 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-42797CRITICAL
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticate
Sep 25, 20249.830NONO
CVE-2024-42777CRITICAL
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code v
Aug 21, 20249.830NONO
CVE-2024-54924CRITICAL
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthor
Dec 9, 20249.829NONO
CVE-2024-54921CRITICAL
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized
Dec 9, 20249.829NONO
CVE-2024-40486CRITICAL
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or p
Aug 12, 20249.829NONO
CVE-2024-42781CRITICAL
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login
Aug 21, 20249.828NONO
CVE-2025-5214CRITICAL
A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cour
May 27, 20259.827NONO
CVE-2024-54920CRITICAL
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get
Dec 9, 20249.827NONO
CVE-2024-50823CRITICAL
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
Nov 14, 20249.827NONO
CVE-2024-42784CRITICAL
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id"
Aug 21, 20249.827NONO
View all 112 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products112 CVEs
39%
41%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.8%)
Network110 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low112 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None80 (71.4%)
Unknown0 (0.0%)
Required32 (28.6%)
Privileges Required
Low34 (30.4%)
High22 (19.6%)
None56 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (112 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lopalopa.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lopalopa — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lopalopa's Products

View all 2 CNAs →

Top CWEs