Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rosariosis

First CVE: Jul 14, 2020Active for: 6 yearsTotal CVEs: 19
46.2
VTI Score
High

Rosariosis is a student information system deployed across educational institutions, and its vulnerability footprint centers on web-application input-handling and access-control flaws endemic to that class of platform. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes include cross-site scripting, SQL injection, improper access control, and exposure of sensitive information, reflecting the data-intensive and web-facing nature of student record management. Defenders should prioritize patching this vendor's disclosures given the sensitive personal and academic data at stake; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rosariosis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2020
6 years ago
Most Recent CVE
May 12, 2023
1,170 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44427CRITICAL
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., S
Nov 29, 20219.869NOYES
CVE-2021-44567CRITICAL
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
Feb 24, 20229.854NOYES
CVE-2020-15718MEDIUM
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability usi
Jul 15, 20206.145NOYES
CVE-2020-15716MEDIUM
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using
Jul 15, 20206.132NOYES
CVE-2022-2714CRITICAL
Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.
Sep 6, 20229.830NONO
CVE-2023-29918MEDIUM
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
May 2, 20235.429NOYES
CVE-2022-2067CRITICAL
SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
Jun 13, 20229.129NONO
CVE-2023-2665HIGH
Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0.
May 12, 20237.525NONO
CVE-2023-0994HIGH
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.
Feb 24, 20237.524NONO
CVE-2021-45416MEDIUM
Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php
Feb 1, 20226.124NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
68%
11%
21%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (36.8%)
Unknown0 (0.0%)
Required12 (63.2%)
Privileges Required
Low7 (36.8%)
High0 (0.0%)
None12 (63.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.5% of CVEs· 96th percentile
ExploitDB
4 CVEs
21.1% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rosariosis.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rosariosis — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rosariosis's Products

View all 3 CNAs →

Top CWEs