Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Social Engine

First CVE: Dec 28, 2007Active for: 19 yearsTotal CVEs: 11

Social Engine is a focused social networking and community platform whose vulnerability footprint centers on application-level input handling and code execution control, with recurring exposure to code injection, path traversal, and SQL injection weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 72% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Social Engine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2007
18 years ago
Most Recent CVE
Apr 23, 2026
92 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-41460CRITICAL
SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is
Apr 23, 20269.832NONO
CVE-2009-0400MEDIUM
SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
Feb 3, 20096.830NOYES
CVE-2026-41461HIGH
SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri requ
Apr 23, 20268.527NONO
CVE-2013-4898MEDIUM
Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated users to execute arbitrary code
Jan 29, 20146.526NOYES
CVE-2007-6581MEDIUM
Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang paramete
Dec 28, 20076.426NOYES
CVE-2012-6721MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4.
Feb 11, 20206.321NONO
CVE-2012-6720MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/
Feb 11, 20206.121NONO
CVE-2008-3298MEDIUM
SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PHP code.
Jul 25, 20086.021NONO
CVE-2008-3297HIGH
Multiple SQL injection vulnerabilities in SocialEngine (SE) before 2.83 allow remote attackers to execute arbitrary SQL commands via (1) an se_user cookie to include/class_user.php
Jul 25, 20087.520NONO
CVE-2008-6121HIGH
CRLF injection vulnerability in SocialEngine (SE) 2.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the PHPSE
Feb 11, 20097.519NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
55%
36%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (36.4%)
Unknown7 (63.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (36.4%)
High0 (0.0%)
Unknown7 (63.6%)
User Interaction
None2 (18.2%)
Unknown7 (63.6%)
Required2 (18.2%)
Privileges Required
Low1 (9.1%)
High0 (0.0%)
None3 (27.3%)
Unknown7 (63.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
27.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Social Engine.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Social Engine — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Social Engine's Products

View all 2 CNAs →

Top CWEs