Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Naviwebs

First CVE: Oct 3, 2018Active for: 8 yearsTotal CVEs: 34
47.1
VTI Score
High

Naviwebs operates a narrowly scoped content management system product line centered on Navigate CMS, which despite its limited portfolio achieves notable prominence in the vulnerability landscape. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and demonstrate a moderate tendency toward public exploit availability. The exposure recurs consistently through application-layer weakness classes including cross-site scripting, SQL injection, path traversal, unrestricted file uploads, and weak password recovery mechanisms—all characteristic flaws in web-facing CMS platforms where input handling and access control are critical. Defenders should prioritize Navigate CMS deployments for patching and treat this vendor's advisories as having upstream implications for sites and integrations that depend on the platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
34
Total CVEs
More Total CVEs than 98% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Naviwebs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2018
7 years ago
Most Recent CVE
Jan 30, 2026
175 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-17552CRITICAL
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
Oct 3, 20189.888NOYES
CVE-2018-17553HIGH
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve re
Oct 3, 20188.885NOYES
CVE-2022-28117MEDIUM
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitr
Apr 28, 20224.949NOYES
CVE-2021-37477CRITICAL
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in
Jul 26, 20219.831NONO
CVE-2020-14067CRITICAL
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload
Jun 15, 20209.831NONO
CVE-2021-37478CRITICAL
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend da
Jul 26, 20219.830NONO
CVE-2021-37476CRITICAL
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query exec
Jul 26, 20219.830NONO
CVE-2021-37475CRITICAL
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query ex
Jul 26, 20219.830NONO
CVE-2021-37473CRITICAL
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sq
Jul 26, 20219.830NONO
CVE-2021-36455HIGH
SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php.
Aug 6, 20218.828NONO
View all 34 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products34 CVEs
56%
21%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network34 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (50.0%)
Unknown0 (0.0%)
Required17 (50.0%)
Privileges Required
Low12 (35.3%)
High4 (11.8%)
None18 (52.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
5.9% of CVEs· 98th percentile
Nuclei
1 CVE
2.9% of CVEs· 95th percentile
ExploitDB
3 CVEs
8.8% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Naviwebs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Naviwebs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Naviwebs's Products

View all 2 CNAs →

Top CWEs