Facilemanager
Facilemanager: vulnerabilities and CVEs
Facilemanager has 5 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30919 | Medium (5.4) | 0.28% | — | Mar 10, 2026 | facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from an untrusted source… |
| CVE-2026-30918 | Medium (6.1) | 0.29% | — | Mar 10, 2026 | facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way… |
| CVE-2024-24573 | High (8.8) | 0.82% | — | Jan 31, 2024 | facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POST request containing user information is sent to the endpoint… |
| CVE-2024-24572 | Medium (6.5) | 0.64% | — | Jan 31, 2024 | facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file… |
| CVE-2024-24571 | Medium (5.4) | 0.42% | — | Jan 31, 2024 | facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present in almost all of the input fields as… |