Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mcgill

First CVE: Feb 25, 2026Active for: 1 yearTotal CVEs: 11
27.8
VTI Score
Low

McGill's vulnerability footprint centers on LORIS, a research data management platform, where disclosures concentrate on access-control and input-handling weaknesses including authorization bypass through user-controlled keys, path traversal, cross-site scripting, and exposure of files and directories to external parties. These patterns reflect the platform's role in managing sensitive research data and underscore the importance of access control and input validation in systems handling restricted information. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
11.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mcgill over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 25, 2026
4 months ago
Most Recent CVE
Apr 9, 2026
106 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-26984HIGH
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26.
Feb 25, 20268.830NONO
CVE-2026-35446HIGH
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before
Apr 8, 20268.629NONO
CVE-2026-34392HIGH
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before
Apr 8, 20267.526NONO
CVE-2026-33350HIGH
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 2
Apr 8, 20267.525NONO
CVE-2026-26985MEDIUM
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 2
Feb 25, 20266.524NONO
CVE-2026-35165MEDIUM
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before
Apr 8, 20266.523NONO
CVE-2026-34985MEDIUM
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before
Apr 8, 20266.523NONO
CVE-2026-35169MEDIUM
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.
Apr 8, 20265.422NONO
CVE-2026-39985MEDIUM
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 2
Apr 9, 20266.121NONO
CVE-2026-35403MEDIUM
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before
Apr 8, 20265.420NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low7 (63.6%)
High0 (0.0%)
None4 (36.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mcgill.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mcgill — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mcgill's Products

View all 1 CNAs →

Top CWEs