viewvc records
21 published records for vendor viewvc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 61.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-399 Resource Management Errors1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2010-0005No exploit | query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, whiviewvc · viewvc · CWE-264 | High7.5 | — | 1.7% | Jan 29, 2010 |
30Monitor | CVE-2007-5743No exploit | viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.viewvc · viewvc · CWE-732 | High7.5 | — | 1.1% | Nov 7, 2019 |
30Monitor | CVE-2025-54141No exploit | ViewVC's standalone server exposes arbitrary server filesystem contentviewvc · viewvc · CWE-22 | High7.5 | — | 0.9% | Jul 22, 2025 |
27Monitor | CVE-2006-5442No exploit | ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-siviewvc · viewvc | Medium6.8 | — | 1.5% | Oct 20, 2006 |
24Monitor | CVE-2017-5938No exploit | Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows reviewvc · viewvc · CWE-79 | Medium6.1 | — | 1.3% | Mar 15, 2017 |
24Monitor | CVE-2023-22456No exploit | ViewVC XSS vulnerability in revision view changed pathsviewvc · viewvc · CWE-79 | Medium6.1 | — | 0.7% | Jan 3, 2023 |
23Monitor | CVE-2008-4325No exploit | lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which alviewvc · viewvc | Medium5.8 | — | 1.4% | Sep 30, 2008 |
21Monitor | CVE-2009-5024No exploit | ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumptviewvc · viewvc · CWE-399 | Medium5.0 | — | 2.6% | May 23, 2011 |
21Monitor | CVE-2010-0004No exploit | ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discoveviewvc · viewvc · CWE-200 | Medium5.0 | — | 2.6% | Jan 29, 2010 |
21Monitor | CVE-2012-3356No exploit | The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows rviewvc · viewvc · CWE-287 | Medium5.0 | — | 2.0% | Jul 22, 2012 |
21Monitor | CVE-2012-3357No exploit | The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copviewvc · viewvc · CWE-200 | Medium5.0 | — | 1.9% | Jul 22, 2012 |
21Monitor | CVE-2009-3619No exploit | Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing viewvc · viewvc | Medium5.0 | — | 1.8% | Nov 9, 2009 |
21Monitor | CVE-2023-22464No exploit | ViewVC XSS vulnerability in revision view changed path "copyfrom" locationsviewvc · viewvc · CWE-79 | Medium5.4 | — | 0.6% | Jan 4, 2023 |
18Monitor | CVE-2012-4533No exploit | Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before viewvc · viewvc · CWE-79 | Medium4.3 | — | 3.1% | Nov 18, 2012 |
18Monitor | CVE-2010-0736No exploit | Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, alviewvc · viewvc · CWE-79 | Medium4.3 | — | 1.7% | Mar 19, 2010 |
17Monitor | CVE-2009-3618No exploit | Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbiviewvc · viewvc · CWE-79 | Medium4.3 | — | 1.6% | Nov 9, 2009 |
17Monitor | CVE-2008-1291No exploit | ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read viewvc · viewvc · CWE-200 | Medium4.3 | — | 1.4% | Mar 24, 2008 |
17Monitor | CVE-2008-1290No exploit | ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attaviewvc · viewvc · CWE-200 | Medium4.3 | — | 1.4% | Mar 24, 2008 |
17Monitor | CVE-2008-1292No exploit | ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtaiviewvc · viewvc · CWE-200 | Medium4.3 | — | 1.4% | Mar 24, 2008 |
14Monitor | CVE-2020-5283No exploit | XSS vulnerability in CVS show_subdir_lastmod supportviewvc · viewvc · CWE-80 | Low3.5 | — | 1.2% | Apr 2, 2020 |
11Monitor | CVE-2010-0132No exploit | Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality viewvc · viewvc · CWE-79 | Low2.6 | — | 2.3% | Mar 31, 2010 |
- CVE-2010-000531Monitor
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, whi
HighCVSS 7.5No exploitEPSS 2%viewvc · viewvcJan 29, 2010
- CVE-2007-574330Monitor
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
HighCVSS 7.5No exploitEPSS 1%viewvc · viewvcNov 7, 2019
- CVE-2025-5414130Monitor
ViewVC's standalone server exposes arbitrary server filesystem content
HighCVSS 7.5No exploitEPSS 1%viewvc · viewvcJul 22, 2025
- CVE-2006-544227Monitor
ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-si
MediumCVSS 6.8No exploitEPSS 2%viewvc · viewvcOct 20, 2006
- CVE-2017-593824Monitor
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows re
MediumCVSS 6.1No exploitEPSS 1%viewvc · viewvcMar 15, 2017
- CVE-2023-2245624Monitor
ViewVC XSS vulnerability in revision view changed paths
MediumCVSS 6.1No exploitEPSS 1%viewvc · viewvcJan 3, 2023
- CVE-2008-432523Monitor
lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which al
MediumCVSS 5.8No exploitEPSS 1%viewvc · viewvcSep 30, 2008
- CVE-2009-502421Monitor
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumpt
MediumCVSS 5.0No exploitEPSS 3%viewvc · viewvcMay 23, 2011
- CVE-2010-000421Monitor
ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discove
MediumCVSS 5.0No exploitEPSS 3%viewvc · viewvcJan 29, 2010
- CVE-2012-335621Monitor
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows r
MediumCVSS 5.0No exploitEPSS 2%viewvc · viewvcJul 22, 2012
- CVE-2012-335721Monitor
The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is cop
MediumCVSS 5.0No exploitEPSS 2%viewvc · viewvcJul 22, 2012
- CVE-2009-361921Monitor
Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing
MediumCVSS 5.0No exploitEPSS 2%viewvc · viewvcNov 9, 2009
- CVE-2023-2246421Monitor
ViewVC XSS vulnerability in revision view changed path "copyfrom" locations
MediumCVSS 5.4No exploitEPSS 1%viewvc · viewvcJan 4, 2023
- CVE-2012-453318Monitor
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before
MediumCVSS 4.3No exploitEPSS 3%viewvc · viewvcNov 18, 2012
- CVE-2010-073618Monitor
Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, al
MediumCVSS 4.3No exploitEPSS 2%viewvc · viewvcMar 19, 2010
- CVE-2009-361817Monitor
Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbi
MediumCVSS 4.3No exploitEPSS 2%viewvc · viewvcNov 9, 2009
- CVE-2008-129117Monitor
ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read
MediumCVSS 4.3No exploitEPSS 1%viewvc · viewvcMar 24, 2008
- CVE-2008-129017Monitor
ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote atta
MediumCVSS 4.3No exploitEPSS 1%viewvc · viewvcMar 24, 2008
- CVE-2008-129217Monitor
ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtai
MediumCVSS 4.3No exploitEPSS 1%viewvc · viewvcMar 24, 2008
- CVE-2020-528314Monitor
XSS vulnerability in CVS show_subdir_lastmod support
LowCVSS 3.5No exploitEPSS 1%viewvc · viewvcApr 2, 2020
- CVE-2010-013211Monitor
Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality
LowCVSS 2.6No exploitEPSS 2%viewvc · viewvcMar 31, 2010