Scilico develops a narrow line of research-support and laboratory-management software products, including i_Librarian and LabWiki, that serve specialized scientific and institutional communities. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through web-tier weakness classes including cross-site scripting, server-side request forgery, CSRF, OS command injection, and exposure of sensitive information—patterns characteristic of web applications handling authentication, data access, and system integration without robust input validation and trust boundaries. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scilico over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000124CRITICAL I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an at | Mar 13, 2018 | 10.0 | 31 | NO | NO |
CVE-2017-1000237CRITICAL I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password. | Nov 17, 2017 | 9.8 | 30 | NO | NO |
CVE-2011-4333MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php | Oct 23, 2017 | 6.1 | 29 | NO | YES |
CVE-2017-1000235CRITICAL I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised. | Nov 17, 2017 | 9.8 | 28 | NO | NO |
CVE-2018-1000141CRITICAL I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining unauthorized access (read, write | Mar 23, 2018 | 9.1 | 27 | NO | NO |
CVE-2018-1000138CRITICAL I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the se | Mar 23, 2018 | 9.1 | 27 | NO | NO |
CVE-2018-1000137HIGH I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the admin being forced to be changed | Mar 23, 2018 | 8.8 | 25 | NO | NO |
CVE-2024-40500HIGH Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component | Aug 12, 2024 | 8.6 | 24 | NO | NO |
CVE-2019-11428MEDIUM I, Librarian 4.10 has XSS via the export.php export_files parameter. | Apr 22, 2019 | 6.1 | 22 | NO | NO |
CVE-2019-11359MEDIUM Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or HTML via the project parameter. | Apr 20, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scilico.
Media articles that mention a CVE ID that affects a product developed by Scilico — matched by CVE ID, not by vendor name.