Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ordasoft

First CVE: Jul 28, 2009Active for: 17 yearsTotal CVEs: 9

Ordasoft develops a focused suite of Joomla extensions for e-commerce and content management, including components for book libraries, real-estate listings, vehicle management, and advertising, deployed across modestly sized web properties. Its vulnerability profile skews toward serious outcomes with elevated critical severity, and the recurring issues center on code injection and SQL injection in user input handling, weaknesses common to web extensions that directly process untrusted data from forms and URLs. Defenders should treat updates to these components as priority patches for any Joomla installation running them; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ordasoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 28, 2009
16 years ago
Most Recent CVE
Feb 17, 2018
3,079 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5971CRITICAL
SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.
Feb 17, 20189.842NOYES
CVE-2018-5982CRITICAL
SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request.
Feb 17, 20189.840NOYES
CVE-2009-2637HIGH
PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic for Joomla! allows remote attackers to execute arbitrary PHP
Jul 28, 20097.530NOYES
CVE-2009-3817HIGH
PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code
Oct 28, 20097.528NOYES
CVE-2009-2635HIGH
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbit
Jul 28, 20097.528NOYES
CVE-2009-2634HIGH
PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PH
Jul 28, 20097.528NOYES
CVE-2009-2633HIGH
PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary P
Jul 28, 20097.528NOYES
CVE-2010-2851HIGH
SQL injection vulnerability in the BookLibrary From Same Author (com_booklibrary) module 1.5 and possibly earlier for Joomla! allows remote attackers to execute arbitrary SQL comma
Jul 25, 20107.522NONO
CVE-2010-1522HIGH
Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQ
Jul 2, 20107.522NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
78%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network2 (22.2%)
Unknown7 (77.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (22.2%)
High0 (0.0%)
Unknown7 (77.8%)
User Interaction
None2 (22.2%)
Unknown7 (77.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (22.2%)
Unknown7 (77.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
77.8% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ordasoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ordasoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ordasoft's Products

View all 1 CNAs →

Top CWEs