Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Refbase

First CVE: Mar 5, 2009Active for: 17 yearsTotal CVEs: 10
40.4
VTI Score
High

Refbase is a modestly represented open-source bibliographic reference management application that sits prominently among academic and research institutions. Its vulnerability profile clusters around web application input-handling and code-injection risks, with recurring issues in cross-site scripting, SQL injection, CSRF, and code-injection weaknesses that are characteristic of server-side web frameworks handling untrusted user input and database queries. The vendor's disclosures have frequently acquired public exploit code, reflecting the accessibility of web-facing instances and the relative ease of weaponizing these classes of flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Refbase over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2009
17 years ago
Most Recent CVE
Sep 28, 2015
3,953 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-6008HIGH
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-
Sep 28, 20157.530NOYES
CVE-2015-7381HIGH
Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary PHP code via the
Sep 28, 20157.529NOYES
CVE-2015-7382HIGH
SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary SQL commands via the defaultCharacterS
Sep 28, 20157.528NOYES
CVE-2015-6009HIGH
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to
Sep 28, 20157.528NOYES
CVE-2015-6007MEDIUM
Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the authentication of arbitrary users.
Sep 28, 20156.818NONO
CVE-2015-6012MEDIUM
Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to redirect users to arbitra
Sep 28, 20155.816NONO
CVE-2015-6011MEDIUM
Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduct XML injection attacks via (1) the id parameter to unapi.ph
Sep 28, 20155.015NONO
CVE-2015-7383MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge through 2015-04-28 allow remote attackers to inject arbi
Sep 28, 20154.314NONO
CVE-2015-6010MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to inject arbit
Sep 28, 20154.314NONO
CVE-2008-6400MEDIUM
Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headerMsg parameter to (1) show.php and (2)
Mar 5, 20094.314NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
40%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown10 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown10 (100.0%)
User Interaction
None0 (0.0%)
Unknown10 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown10 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
40.0% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Refbase.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Refbase — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Refbase's Products

View all 2 CNAs →

Top CWEs