Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sfu

First CVE: Jun 12, 2018Active for: 8 yearsTotal CVEs: 18
14.0
VTI Score
Low

SFU maintains a modestly represented portfolio of academic publishing and web application platforms, most notably the widely adopted Open Journal System and its associated PKP Web Application Library. The vendor's vulnerability exposure centers on application-layer input handling and request validation, with recurring weakness classes including cross-site scripting, cross-site request forgery, code injection, and deserialization flaws that are characteristic of web-facing PHP-based software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sfu over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2018
8 years ago
Most Recent CVE
Mar 1, 2024
875 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-19909HIGH
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report g
Dec 19, 20198.826NONO
CVE-2023-5897HIGH
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.
Nov 1, 20238.824NONO
CVE-2023-5893HIGH
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
Nov 1, 20238.824NONO
CVE-2023-5626HIGH
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.
Oct 18, 20238.824NONO
CVE-2024-25436MEDIUM
A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into th
Mar 1, 20246.118NONO
CVE-2023-5900MEDIUM
Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
Nov 7, 20234.318NONO
CVE-2023-47271MEDIUM
PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML docume
Nov 6, 20235.318NONO
CVE-2023-5890MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
Nov 1, 20235.418NONO
CVE-2018-12229MEDIUM
Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML
Jun 12, 20186.118NONO
CVE-2023-5904MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
Nov 7, 20235.417NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
78%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (5.6%)
Unknown0 (0.0%)
Required17 (94.4%)
Privileges Required
Low8 (44.4%)
High1 (5.6%)
None9 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sfu.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sfu — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sfu's Products

View all 2 CNAs →

Top CWEs