Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Weberp

First CVE: Nov 22, 2018Active for: 8 yearsTotal CVEs: 11
49.4
VTI Score
High

Weberp is a small enterprise resource planning and accounting application with a narrow product footprint that nonetheless sits among the more prominent in its category. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the application's exposure to untrusted input and the severity impact of flaws in financial and business-logic systems; the recurring weakness classes—SQL injection, insecure file accessibility, unsafe inclusion of untrusted functionality, and improper permission assignment—are characteristic of legacy web applications with evolving security awareness. Defenders should treat this vendor's advisories as high-priority and verify patch deployment across deployed instances; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Weberp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2018
7 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-13292CRITICAL
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goe
Jul 4, 20199.846NOYES
CVE-2015-10018CRITICAL
A vulnerability has been found in DBRisinajumi d2files and classified as critical. Affected by this vulnerability is the function actionUpload/actionDownloadFile of the file contro
Jan 6, 20239.830NONO
CVE-2025-46052CRITICAL
An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by injecting a crafted payload into
May 15, 20259.827NONO
CVE-2020-37082HIGH
webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly ac
Feb 3, 20267.525NONO
CVE-2019-7755HIGH
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka
Mar 30, 20208.824NONO
CVE-2018-19436HIGH
An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter.
Nov 22, 20187.223NONO
CVE-2018-19435HIGH
An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.
Nov 22, 20187.223NONO
CVE-2018-19434HIGH
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_
Nov 22, 20187.223NONO
CVE-2018-20420MEDIUM
In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and th
Dec 24, 20184.918NONO
CVE-2025-46053MEDIUM
A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and R
May 15, 20255.117NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
27%
45%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (18.2%)
High4 (36.4%)
None5 (45.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Weberp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Weberp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Weberp's Products

View all 3 CNAs →

Top CWEs