Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webidsupport

First CVE: Aug 28, 2009Active for: 17 yearsTotal CVEs: 17
52.2
VTI Score
TOP TARGET

Webidsupport maintains a narrowly focused product line centered on the WebID platform, which appears to serve identity and access management functions in web environments. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and frequently acquire public exploit code; the recurring exposure centers on web application input-handling and access-control weaknesses including cross-site scripting, SQL injection, authorization bypass, code injection, and information disclosure that are characteristic of authentication and session-management systems. Defenders should prioritize patching for internet-reachable identity platforms from this vendor; live exploitation status and severity figures are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webidsupport over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 28, 2009
16 years ago
Most Recent CVE
May 22, 2024
793 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-23359CRITICAL
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-iden
Jan 27, 20219.830NONO
CVE-2022-41477CRITICAL
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via them
Oct 14, 20229.128NONO
CVE-2008-7119HIGH
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Aug 28, 20097.528NOYES
CVE-2008-7116HIGH
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.
Aug 28, 20097.528NOYES
CVE-2018-1000867HIGH
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. Thi
Dec 20, 20188.827NONO
CVE-2014-5101MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email,
Jul 25, 20144.327NOYES
CVE-2024-35409CRITICAL
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
May 22, 20249.826NONO
CVE-2023-47397CRITICAL
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
Nov 8, 20239.826NONO
CVE-2010-4873MEDIUM
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Oct 7, 20114.325NOYES
CVE-2024-32166HIGH
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal p
Apr 19, 20248.824NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
41%
35%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (52.9%)
Unknown8 (47.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (52.9%)
High0 (0.0%)
Unknown8 (47.1%)
User Interaction
None7 (41.2%)
Unknown8 (47.1%)
Required2 (11.8%)
Privileges Required
Low2 (11.8%)
High0 (0.0%)
None7 (41.2%)
Unknown8 (47.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
35.3% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webidsupport.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webidsupport — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webidsupport's Products

View all 1 CNAs →

Top CWEs