ArchiveBox records
2 published records for vendor archivebox.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-42601No exploit | ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddViewarchivebox · archivebox · CWE-88 | Critical9.3 | — | 0.6% | May 9, 2026 |
21Monitor | CVE-2023-45815No exploit | ArchiveBox: Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins contextarchivebox · archivebox · CWE-79 | Medium5.4 | — | 0.7% | Oct 19, 2023 |
- CVE-2026-4260137Monitor
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
CriticalCVSS 9.3No exploitEPSS 1%archivebox · archiveboxMay 9, 2026
- CVE-2023-4581521Monitor
ArchiveBox: Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins context
MediumCVSS 5.4No exploitEPSS 1%archivebox · archiveboxOct 19, 2023