Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thephpfactory

First CVE: Sep 28, 2018Active for: 8 yearsTotal CVEs: 11
60.1
VTI Score
TOP TARGET

Thephpfactory develops a suite of web-based factory and marketplace applications, including article, auction, collection, and jobs management systems, that present a focused but prominent attack surface centered on SQL-injectable input handling. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with the recurring weakness class of SQL injection reflecting the characteristic parsing and query-construction risks inherent to dynamically generated database operations in web applications. Live severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
9.8
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thephpfactory over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 28, 2018
7 years ago
Most Recent CVE
Jun 19, 2019
2,592 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-17376CRITICAL
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
Sep 28, 20189.843NOYES
CVE-2018-17385CRITICAL
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
Sep 28, 20189.841NOYES
CVE-2018-17384CRITICAL
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
Sep 28, 20189.841NOYES
CVE-2018-17378CRITICAL
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
Sep 28, 20189.841NOYES
CVE-2018-17383CRITICAL
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
Sep 28, 20189.840NOYES
CVE-2018-17382CRITICAL
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
Sep 28, 20189.840NOYES
CVE-2018-17380CRITICAL
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
Sep 28, 20189.840NOYES
CVE-2018-17379CRITICAL
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
Sep 28, 20189.840NOYES
CVE-2018-17386CRITICAL
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
Jun 19, 20199.829NONO
CVE-2018-17381CRITICAL
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
Jun 19, 20199.829NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
Critical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
72.7% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thephpfactory.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thephpfactory — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thephpfactory's Products

View all 1 CNAs →

Top CWEs