Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sourceforge

First CVE: May 3, 2001Active for: 25 yearsTotal CVEs: 13
29.5
VTI Score
Low

Sourceforge hosts a modestly represented portfolio of open-source and community projects spanning utilities, peer-to-peer applications, and web-based tools, with recurring vulnerabilities clustered around input validation, authentication, and path-traversal weaknesses typical of web-facing and user-interactive software. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility of source-code repositories and the appeal of these applications to security researchers and attackers. Defenders should monitor updates from projects of operational interest on this platform and prioritize patching for internet-exposed instances; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sourceforge over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2001
25 years ago
Most Recent CVE
Feb 18, 2009
6,365 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-4837HIGH
snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of
Dec 31, 200510.030NONO
CVE-2008-2298HIGH
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.
May 18, 20087.529NOYES
CVE-2007-1572MEDIUM
SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than
Mar 21, 20076.826NOYES
CVE-2008-0501MEDIUM
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the t
Jan 30, 20085.824NOYES
CVE-2008-2503HIGH
Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.
May 29, 20089.323NONO
CVE-2002-2362MEDIUM
Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.
Dec 31, 20024.321NOYES
CVE-2001-0234HIGH
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.
May 3, 20017.520NONO
CVE-2007-1466MEDIUM
Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause
Mar 16, 20076.819NONO
CVE-2007-1135MEDIUM
Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2
Mar 2, 20076.819NONO
CVE-2002-2364MEDIUM
Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.
Dec 31, 20024.318NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
69%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown13 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown13 (100.0%)
User Interaction
None0 (0.0%)
Unknown13 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown13 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
30.8% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sourceforge.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sourceforge — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sourceforge's Products

View all 1 CNAs →

Top CWEs