Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ushahidi

First CVE: Aug 12, 2012Active for: 14 yearsTotal CVEs: 11
31.8
VTI Score
Medium

Ushahidi develops a crisis-mapping and crowdsourced information platform intended for humanitarian response and social accountability in conflict and disaster contexts, with vulnerabilities concentrating in a focused product line. The recurring weakness classes reflect common web-application challenges: SQL injection, authentication bypasses, cross-site scripting, and sensitive information exposure, indicating input-handling and session-management demands typical of data-aggregation platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ushahidi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2012
13 years ago
Most Recent CVE
Feb 4, 2020
2,362 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-5618CRITICAL
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
Feb 4, 20209.829NONO
CVE-2012-3471HIGH
Multiple SQL injection vulnerabilities in the edit functions in (1) application/controllers/admin/reports.php and (2) application/controllers/members/reports.php in the Ushahidi Pl
Aug 12, 20127.524NONO
CVE-2012-3475HIGH
The installer in the Ushahidi Platform before 2.5 omits certain calls to the exit function, which allows remote attackers to obtain administrative privileges via unspecified vector
Aug 12, 20127.522NONO
CVE-2012-3470HIGH
Multiple SQL injection vulnerabilities in application/libraries/api/MY_Countries_Api_Object.php in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL
Aug 12, 20127.522NONO
CVE-2012-3469HIGH
Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the messages admin fu
Aug 12, 20127.522NONO
CVE-2012-3473MEDIUM
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate
Aug 12, 20126.421NONO
CVE-2012-3472MEDIUM
The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delet
Aug 12, 20126.421NONO
CVE-2012-3468HIGH
Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the verify function i
Aug 12, 20127.521NONO
CVE-2013-2025MEDIUM
Cross-site scripting (XSS) vulnerability in Ushahidi Platform 2.5.x through 2.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Apr 25, 20144.319NONO
CVE-2012-3474MEDIUM
The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mai
Aug 12, 20125.018NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
9%
36%
45%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (9.1%)
Unknown10 (90.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (9.1%)
High0 (0.0%)
Unknown10 (90.9%)
User Interaction
None1 (9.1%)
Unknown10 (90.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (9.1%)
Unknown10 (90.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ushahidi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ushahidi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ushahidi's Products

View all 1 CNAs →

Top CWEs