Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Scilico

First CVE: Oct 23, 2017Active for: 9 yearsTotal CVEs: 15
33.5
VTI Score
Medium

Scilico develops a narrow line of research-support and laboratory-management software products, including i_Librarian and LabWiki, that serve specialized scientific and institutional communities. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through web-tier weakness classes including cross-site scripting, server-side request forgery, CSRF, OS command injection, and exposure of sensitive information—patterns characteristic of web applications handling authentication, data access, and system integration without robust input validation and trust boundaries. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Scilico over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2017
8 years ago
Most Recent CVE
Aug 12, 2024
710 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1000124CRITICAL
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an at
Mar 13, 201810.031NONO
CVE-2017-1000237CRITICAL
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.
Nov 17, 20179.830NONO
CVE-2011-4333MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php
Oct 23, 20176.129NOYES
CVE-2017-1000235CRITICAL
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.
Nov 17, 20179.828NONO
CVE-2018-1000141CRITICAL
I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining unauthorized access (read, write
Mar 23, 20189.127NONO
CVE-2018-1000138CRITICAL
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the se
Mar 23, 20189.127NONO
CVE-2018-1000137HIGH
I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the admin being forced to be changed
Mar 23, 20188.825NONO
CVE-2024-40500HIGH
Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component
Aug 12, 20248.624NONO
CVE-2019-11428MEDIUM
I, Librarian 4.10 has XSS via the export.php export_files parameter.
Apr 22, 20196.122NONO
CVE-2019-11359MEDIUM
Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or HTML via the project parameter.
Apr 20, 20196.122NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
53%
13%
33%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network14 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (40.0%)
Unknown0 (0.0%)
Required9 (60.0%)
Privileges Required
Low1 (6.7%)
High0 (0.0%)
None14 (93.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Scilico.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Scilico — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Scilico's Products

View all 3 CNAs →

Top CWEs