Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oretnom23

First CVE: Oct 29, 2021Active for: 5 yearsTotal CVEs: 761
43.2
VTI Score
High

Oretnom23's vulnerability footprint spans a moderate but broadly represented collection of web-based business and administrative applications, including e-commerce platforms, management systems for human resources and laboratory operations, and food-ordering solutions that serve educational and commercial environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate heavily in application-layer input handling, encompassing SQL injection, cross-site scripting, injection flaws, unrestricted file uploads, and cross-site request forgery—a cluster of weaknesses typical of web applications with insufficient input validation and output encoding. The recurring pattern reflects a structural vulnerability in the vendor's development practices: these weakness classes are persistent across multiple distinct product lines, indicating that foundational security controls around parameterized queries, context-aware output encoding, and file-type validation are not uniformly applied. Defenders should treat Oretnom23 product deployments as high-risk and prioritize remediation of SQL-injection and XSS findings, given the vendor's sustained exposure to these classes and the critical outcomes they tend to produce. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
761
Total CVEs
More Total CVEs than 100% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oretnom23 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 29, 2021
4 years ago
Most Recent CVE
Apr 13, 2026
102 days ago

Products(112 total)

Top CVEs

Signals from CVEs in this vendor scope (761 CVEs).

761 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-40471CRITICAL
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php
Oct 31, 20229.852NOYES
CVE-2021-42580CRITICAL
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php)
Nov 15, 20219.847NOYES
CVE-2023-1826CRITICAL
A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file php-ocls\admin\system_
Apr 4, 20239.844NOYES
CVE-2021-44653CRITICAL
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerabilit
Dec 15, 20219.843NOYES
CVE-2021-43140CRITICAL
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
Nov 3, 20219.843NOYES
CVE-2023-33592CRITICAL
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
Jun 28, 20239.839NOYES
CVE-2022-2297HIGH
A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.p
Jul 12, 20228.839NOYES
CVE-2023-34581CRITICAL
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2
Jun 12, 20239.838NOYES
CVE-2024-0264CRITICAL
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php.
Jan 7, 20249.837NONO
CVE-2026-2848CRITICAL
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register
Feb 20, 20269.835NONO
View all 761 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products761 CVEs
31%
27%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (0.8%)
Network755 (99.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low759 (99.7%)
High2 (0.3%)
Unknown0 (0.0%)
User Interaction
None563 (74.0%)
Unknown0 (0.0%)
Required198 (26.0%)
Privileges Required
Low217 (28.5%)
High73 (9.6%)
None471 (61.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (761 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
0.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oretnom23.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oretnom23 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oretnom23's Products

View all 3 CNAs →

Top CWEs