Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Projectpier

First CVE: Dec 15, 2008Active for: 18 yearsTotal CVEs: 10
35.7
VTI Score
Medium

Projectpier is a web-based project management application with a narrow product scope but meaningful presence in self-hosted collaboration environments. Vulnerabilities affecting the vendor skew toward critical severity and frequently acquire public exploit code, with recurring weaknesses concentrated in input validation and handling across its application layer—including cross-site scripting, SQL injection, CSRF, file-upload restrictions, and sensitive-information exposure. Defenders deploying this software should prioritize patching and restrict network access to trusted users; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Projectpier over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2008
17 years ago
Most Recent CVE
Aug 8, 2025
350 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-10036CRITICAL
Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to validate the file type or enfor
Aug 8, 20259.346NOYES
CVE-2018-10759CRITICAL
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the
May 16, 20189.829NONO
CVE-2018-10760HIGH
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a file with
May 16, 20188.822NONO
CVE-2008-5584MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone,
Dec 15, 20084.322NOYES
CVE-2015-2796MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script or HTML via the search_for parameter to (
Feb 2, 20186.119NONO
CVE-2008-5583MEDIUM
Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an administrator via the query string, as
Dec 15, 20086.818NONO
CVE-2011-3797MEDIUM
ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonst
Sep 24, 20115.017NONO
CVE-2013-3636MEDIUM
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
Feb 7, 20205.416NONO
CVE-2013-3637MEDIUM
ProjectPier 0.8.8 does not use the Secure flag for cookies
Feb 7, 20205.415NONO
CVE-2013-3635MEDIUM
ProjectPier 0.8.8 has stored XSS
Feb 7, 20205.415NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
70%
10%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (70.0%)
Unknown3 (30.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (70.0%)
High0 (0.0%)
Unknown3 (30.0%)
User Interaction
None3 (30.0%)
Unknown3 (30.0%)
Required4 (40.0%)
Privileges Required
Low4 (40.0%)
High0 (0.0%)
None3 (30.0%)
Unknown3 (30.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
10.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Projectpier.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Projectpier — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Projectpier's Products

View all 2 CNAs →

Top CWEs