Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpgacl Project

First CVE: Feb 1, 2021Active for: 5 yearsTotal CVEs: 7

Phpgacl Project maintains a narrowly scoped access-control library that, despite limited product breadth, is embedded in healthcare and enterprise systems where authentication and authorization decisions are critical. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through application-layer input-handling weaknesses including cross-site scripting, SQL injection, and open redirect flaws that arise from the library's web-facing authorization interface. Defenders should assess whether downstream products bundle this library and prioritize remediation where the library handles untrusted user input or session data; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpgacl Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2021
5 years ago
Most Recent CVE
Apr 18, 2022
1,558 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-13562MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker
Feb 1, 20216.156NONO
CVE-2020-13564MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker
Feb 1, 20216.155NONO
CVE-2020-13563MEDIUM
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker
Feb 1, 20216.155NONO
CVE-2020-13568HIGH
SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerabilit
Apr 13, 20218.836NONO
CVE-2020-13567CRITICAL
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vu
Apr 18, 20229.830NONO
CVE-2020-13566HIGH
SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerabili
Apr 13, 20218.822NONO
CVE-2020-13565MEDIUM
An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f9
Feb 10, 20216.117NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
57%
29%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (42.9%)
Unknown0 (0.0%)
Required4 (57.1%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpgacl Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpgacl Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpgacl Project's Products

View all 1 CNAs →

Top CWEs