sourcefabric records
26 published records for vendor sourcefabric.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-94 Improper Control of Generation of Code ('Code Injection')7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-36749No exploit | RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php.sourcefabric · rpi-jukebox-rfid · CWE-78 | Critical9.8 | — | 2.7% | Aug 30, 2022 |
39Monitor | CVE-2024-0714No exploit | MiczFlor RPi-Jukebox-RFID HTTP Request userScripts.php os command injectionsourcefabric · phoniebox · CWE-78 | Critical9.8 | — | 1.6% | Jan 19, 2024 |
39Monitor | CVE-2024-41368No exploit | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.phpsourcefabric · phoniebox · CWE-94 | Critical9.8 | — | 0.9% | Aug 29, 2024 |
39Monitor | CVE-2024-41367No exploit | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.psourcefabric · phoniebox · CWE-94 | Critical9.8 | — | 0.9% | Aug 29, 2024 |
39Monitor | CVE-2024-41366No exploit | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.phpsourcefabric · phoniebox · CWE-94 | Critical9.8 | — | 0.9% | Aug 29, 2024 |
39Monitor | CVE-2024-41364No exploit | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.phpsourcefabric · phoniebox · CWE-94 | Critical9.8 | — | 0.9% | Aug 29, 2024 |
39Monitor | CVE-2024-41369No exploit | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.phpsourcefabric · phoniebox · CWE-94 | Critical9.8 | — | 0.9% | Aug 29, 2024 |
39Monitor | CVE-2024-41361No exploit | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.phpsourcefabric · phoniebox · CWE-94 | Critical9.8 | — | 0.9% | Aug 29, 2024 |
38Monitor | CVE-2024-3799No exploit | Shell command injection in Phonieboxphoniebox · phoniebox · CWE-78 | High8.7 | — | 14.6% | Jul 10, 2024 |
34Monitor | CVE-2024-3798No exploit | Insecure handling of GET argument in Phonieboxphoniebox · phoniebox · CWE-78 | High8.7 | — | 0.5% | Jul 10, 2024 |
31Monitor | CVE-2012-1934Proof of concept | SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitsourcefabric · newscoop · CWE-89 | High7.5 | — | 2.5% | Aug 27, 2012 |
31Monitor | CVE-2020-11807No exploit | Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrarsourcefabric · newscoop · CWE-434 | High7.8 | — | 0.7% | May 19, 2020 |
30Monitor | CVE-2025-63951No exploit | An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0asourcefabric · phoniebox · CWE-502 | High7.5 | — | 0.5% | Dec 18, 2025 |
29Monitor | CVE-2012-1933Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow sourcefabric · newscoop · CWE-94 | Medium6.8 | — | 5.6% | Aug 27, 2012 |
18Monitor | CVE-2012-1935Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arbsourcefabric · newscoop · CWE-79 | Medium4.3 | — | 2.9% | Aug 27, 2012 |
18Monitor | CVE-2012-4679Proof of concept | Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web script sourcefabric · newscoop · CWE-79 | Medium4.3 | — | 2.4% | Aug 27, 2012 |
18Monitor | CVE-2013-0730No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or Hsourcefabric · newscoop · CWE-79 | Medium4.3 | — | 1.8% | Feb 21, 2013 |
17Monitor | CVE-2010-4973No exploit | Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or Hsourcefabric · campsite · CWE-79 | Medium4.3 | — | 0.9% | Nov 1, 2011 |
11Monitor | CVE-2025-10327Proof of concept | MiczFlor RPi-Jukebox-RFID shuffle.php os command injectionsourcefabric · rpi-jukebox-rfid · CWE-77 | Low2.1 | — | 10.2% | Sep 12, 2025 |
11Monitor | CVE-2025-10328No exploit | MiczFlor RPi-Jukebox-RFID playsinglefile.php os command injectionsourcefabric · rpi-jukebox-rfid · CWE-77 | Low2.1 | — | 9.4% | Sep 12, 2025 |
10Monitor | CVE-2025-10326No exploit | MiczFlor RPi-Jukebox-RFID single.php os command injectionsourcefabric · rpi-jukebox-rfid · CWE-77 | Low2.1 | — | 7.1% | Sep 12, 2025 |
8Monitor | CVE-2025-10370Proof of concept | MiczFlor RPi-Jukebox-RFID userScripts.php cross site scriptingsourcefabric · rpi-jukebox-rfid · CWE-79 | Low2.0 | — | 0.7% | Sep 13, 2025 |
8Monitor | CVE-2025-10369No exploit | MiczFlor RPi-Jukebox-RFID cardRegisterNew.php cross site scriptingsourcefabric · rpi-jukebox-rfid · CWE-79 | Low2.0 | — | 0.3% | Sep 13, 2025 |
8Monitor | CVE-2025-10367No exploit | MiczFlor RPi-Jukebox-RFID cardEdit.php cross site scriptingsourcefabric · rpi-jukebox-rfid · CWE-79 | Low2.0 | — | 0.3% | Sep 13, 2025 |
8Monitor | CVE-2025-10368No exploit | MiczFlor RPi-Jukebox-RFID manageFilesFolders.php cross site scriptingsourcefabric · rpi-jukebox-rfid · CWE-79 | Low2.0 | — | 0.3% | Sep 13, 2025 |
- CVE-2022-3674940Plan
RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php.
CriticalCVSS 9.8No exploitEPSS 3%sourcefabric · rpi-jukebox-rfidAug 30, 2022
- CVE-2024-071439Monitor
MiczFlor RPi-Jukebox-RFID HTTP Request userScripts.php os command injection
CriticalCVSS 9.8No exploitEPSS 2%sourcefabric · phonieboxJan 19, 2024
- CVE-2024-4136839Monitor
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php
CriticalCVSS 9.8No exploitEPSS 1%sourcefabric · phonieboxAug 29, 2024
- CVE-2024-4136739Monitor
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.p
CriticalCVSS 9.8No exploitEPSS 1%sourcefabric · phonieboxAug 29, 2024
- CVE-2024-4136639Monitor
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php
CriticalCVSS 9.8No exploitEPSS 1%sourcefabric · phonieboxAug 29, 2024
- CVE-2024-4136439Monitor
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php
CriticalCVSS 9.8No exploitEPSS 1%sourcefabric · phonieboxAug 29, 2024
- CVE-2024-4136939Monitor
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php
CriticalCVSS 9.8No exploitEPSS 1%sourcefabric · phonieboxAug 29, 2024
- CVE-2024-4136139Monitor
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php
CriticalCVSS 9.8No exploitEPSS 1%sourcefabric · phonieboxAug 29, 2024
- CVE-2024-379938Monitor
Shell command injection in Phoniebox
HighCVSS 8.7No exploitEPSS 15%phoniebox · phonieboxJul 10, 2024
- CVE-2024-379834Monitor
Insecure handling of GET argument in Phoniebox
HighCVSS 8.7No exploitEPSS 0%phoniebox · phonieboxJul 10, 2024
- CVE-2012-193431Monitor
SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbit
HighCVSS 7.5Proof of conceptEPSS 3%sourcefabric · newscoopAug 27, 2012
- CVE-2020-1180731Monitor
Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrar
HighCVSS 7.8No exploitEPSS 1%sourcefabric · newscoopMay 19, 2020
- CVE-2025-6395130Monitor
An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0a
HighCVSS 7.5No exploitEPSS 1%sourcefabric · phonieboxDec 18, 2025
- CVE-2012-193329Monitor
Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow
MediumCVSS 6.8Proof of conceptEPSS 6%sourcefabric · newscoopAug 27, 2012
- CVE-2012-193518Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arb
MediumCVSS 4.3Proof of conceptEPSS 3%sourcefabric · newscoopAug 27, 2012
- CVE-2012-467918Monitor
Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 2%sourcefabric · newscoopAug 27, 2012
- CVE-2013-073018Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or H
MediumCVSS 4.3No exploitEPSS 2%sourcefabric · newscoopFeb 21, 2013
- CVE-2010-497317Monitor
Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or H
MediumCVSS 4.3No exploitEPSS 1%sourcefabric · campsiteNov 1, 2011
- CVE-2025-1032711Monitor
MiczFlor RPi-Jukebox-RFID shuffle.php os command injection
LowCVSS 2.1Proof of conceptEPSS 10%sourcefabric · rpi-jukebox-rfidSep 12, 2025
- CVE-2025-1032811Monitor
MiczFlor RPi-Jukebox-RFID playsinglefile.php os command injection
LowCVSS 2.1No exploitEPSS 9%sourcefabric · rpi-jukebox-rfidSep 12, 2025
- CVE-2025-1032610Monitor
MiczFlor RPi-Jukebox-RFID single.php os command injection
LowCVSS 2.1No exploitEPSS 7%sourcefabric · rpi-jukebox-rfidSep 12, 2025
- CVE-2025-103708Monitor
MiczFlor RPi-Jukebox-RFID userScripts.php cross site scripting
LowCVSS 2.0Proof of conceptEPSS 1%sourcefabric · rpi-jukebox-rfidSep 13, 2025
- CVE-2025-103698Monitor
MiczFlor RPi-Jukebox-RFID cardRegisterNew.php cross site scripting
LowCVSS 2.0No exploitEPSS 0%sourcefabric · rpi-jukebox-rfidSep 13, 2025
- CVE-2025-103678Monitor
MiczFlor RPi-Jukebox-RFID cardEdit.php cross site scripting
LowCVSS 2.0No exploitEPSS 0%sourcefabric · rpi-jukebox-rfidSep 13, 2025
- CVE-2025-103688Monitor
MiczFlor RPi-Jukebox-RFID manageFilesFolders.php cross site scripting
LowCVSS 2.0No exploitEPSS 0%sourcefabric · rpi-jukebox-rfidSep 13, 2025