Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sweetphp

First CVE: Apr 20, 2006Active for: 20 yearsTotal CVEs: 8

Sweetphp's vulnerability footprint centers on a narrowly scoped product line dominated by calendar and scheduling applications such as TotalCalendar, which despite modest volume occupy a position of prominence within web-application deployments. The recurring exposure involves recurrent input-handling and access-control weaknesses including path traversal, improper authentication, code injection, and SQL injection, reflecting the user-input and database integration points typical of calendar and event-management software. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sweetphp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 20, 2006
20 years ago
Most Recent CVE
Jul 28, 2010
5,840 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-3515HIGH
SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Jul 3, 200710.036NOYES
CVE-2009-4974HIGH
Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot d
Jul 28, 20107.532NOYES
CVE-2009-4973HIGH
SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.
Jul 28, 20107.530NOYES
CVE-2009-4929HIGH
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwords via the newPW1 and newPW2 pa
Jul 12, 20107.530NOYES
CVE-2006-7055MEDIUM
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a diffe
Feb 24, 20076.828NOYES
CVE-2009-1406MEDIUM
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the include para
Apr 24, 20096.827NOYES
CVE-2006-1922MEDIUM
PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.
Apr 20, 20066.426NOYES
CVE-2009-4928HIGH
PHP remote file inclusion vulnerability in config.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter, a different vec
Jul 12, 20107.521NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
63%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
87.5% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sweetphp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sweetphp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sweetphp's Products

View all 1 CNAs →

Top CWEs