Sourcefabric maintains a small but prominent portfolio of open-source media and publishing platforms, including content-management systems such as Newscoop and Campsite and specialized audio applications like Phoniebox, which collectively serve niche but engaged communities. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the injection-prone nature of web-facing publishing and media-serving architectures. The exposure recurs through code-injection, cross-site scripting, OS command injection, and deserialization weaknesses that are characteristic of server-side scripting and media-handling frameworks that accept and process untrusted user input and configuration data. Defenders deploying these platforms in production should prioritize inventory and patching, particularly for internet-exposed instances; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sourcefabric over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10327CRITICAL A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/api/playlist/shuffle.php. Ex | Sep 12, 2025 | 9.8 | 48 | NO | YES |
CVE-2025-10328CRITICAL A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/api/playlist/playsingl | Sep 12, 2025 | 9.8 | 39 | NO | NO |
CVE-2025-10326CRITICAL A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single.php. Performing manipulation o | Sep 12, 2025 | 9.8 | 33 | NO | NO |
CVE-2012-1934HIGH SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitrary SQL commands via the f_country_code | Aug 27, 2012 | 7.5 | 33 | NO | YES |
CVE-2012-1933MEDIUM Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote attackers to execute arbitrary PH | Aug 27, 2012 | 6.8 | 33 | NO | YES |
CVE-2022-36749CRITICAL RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload | Aug 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-41369CRITICAL RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php | Aug 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-41368CRITICAL RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php | Aug 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-41364CRITICAL RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php | Aug 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-10370MEDIUM A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argume | Sep 13, 2025 | 5.4 | 29 | NO | YES |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sourcefabric.
Media articles that mention a CVE ID that affects a product developed by Sourcefabric — matched by CVE ID, not by vendor name.