Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Websitebaker

First CVE: Aug 3, 2005Active for: 21 yearsTotal CVEs: 22
46.4
VTI Score
High

Websitebaker is a modestly represented content management and website-building platform whose vulnerability profile concentrates in a single product line. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through characteristic web-application weakness classes including cross-site scripting, SQL injection, unrestricted file upload, cross-site request forgery, and code injection—patterns typical of server-side frameworks handling user-generated content and database interaction. Defenders deploying this platform should prioritize input validation and output encoding hardening, and track upstream releases closely; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 95% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Websitebaker over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2005
20 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7410CRITICAL
Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via
Apr 3, 20179.832NONO
CVE-2017-9360CRITICAL
WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.
Jun 2, 20179.831NONO
CVE-2017-9771CRITICAL
install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or database_password parameter.
Jun 21, 20179.830NONO
CVE-2020-25990CRITICAL
WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the a
Oct 1, 20209.829NONO
CVE-2014-9242HIGH
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
Dec 3, 20147.528NOYES
CVE-2005-4140HIGH
SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the use
Dec 9, 20057.528NOYES
CVE-2011-2934HIGH
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.
Jan 14, 20208.827NONO
CVE-2021-47788HIGH
WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can explo
Jan 16, 20268.825NONO
CVE-2011-4322HIGH
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
Jan 21, 20207.524NONO
CVE-2011-2933HIGH
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5,
Jan 14, 20207.224NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
55%
27%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (59.1%)
Unknown9 (40.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (59.1%)
High0 (0.0%)
Unknown9 (40.9%)
User Interaction
None8 (36.4%)
Unknown9 (40.9%)
Required5 (22.7%)
Privileges Required
Low4 (18.2%)
High1 (4.5%)
None8 (36.4%)
Unknown9 (40.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Websitebaker.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Websitebaker — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Websitebaker's Products

View all 3 CNAs →

Top CWEs