Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Schools Alert Management Script Project

First CVE: Feb 12, 2018Active for: 8 yearsTotal CVEs: 7

The Schools Alert Management Script Project maintains a focused educational alert-notification application that has attracted vulnerabilities skewing strongly toward critical severity. Its disclosures recur around input-handling and file-management weaknesses—SQL injection, path traversal, and unrestricted file uploads—that are endemic to web-facing administrative scripts handling sensitive school communications. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
7.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
9.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Schools Alert Management Script Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2018
8 years ago
Most Recent CVE
Jun 8, 2018
2,968 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-12054HIGH
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.
Jun 8, 20187.562NOYES
CVE-2018-12052CRITICAL
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
Jun 8, 20189.839NOYES
CVE-2018-12055CRITICAL
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and s
Jun 8, 20189.838NOYES
CVE-2018-12053HIGH
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal.
Jun 8, 20187.537NOYES
CVE-2018-6859CRITICAL
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter.
Feb 23, 20189.828NONO
CVE-2018-12051CRITICAL
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as demonstrated by a .php file wit
Jun 8, 20189.827NONO
CVE-2018-6860HIGH
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a profile picture.
Feb 12, 20188.825NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
57%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
4 CVEs
57.1% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Schools Alert Management Script Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Schools Alert Management Script Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Schools Alert Management Script Project's Products

View all 1 CNAs →

Top CWEs