web2py records
13 published records for vendor web2py.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 46.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-3957Proof of concept | The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, wweb2py · web2py · CWE-502 | Critical9.8 | — | 4.9% | Feb 6, 2018 |
40Plan | CVE-2023-45158Proof of concept | An OS command injection vulnerability exists in web2py 2.24.1 and earlier.web2py · web2py · CWE-78 | Critical9.8 | — | 3.7% | Oct 16, 2023 |
40Plan | CVE-2016-3953No exploit | The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a harweb2py · web2py · CWE-798 | Critical9.8 | — | 3.3% | Feb 6, 2018 |
40Plan | CVE-2016-10321No exploit | web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-forweb2py · web2py · CWE-254 | Critical9.8 | — | 2.6% | Apr 10, 2017 |
36Monitor | CVE-2016-4808Proof of concept | Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a loggedweb2py · web2py · CWE-352 | High8.8 | — | 1.8% | Jan 11, 2017 |
33Monitor | CVE-2016-4806Proof of concept | Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access wweb2py · web2py · CWE-200 | High7.5 | — | 10.1% | Jan 11, 2017 |
31Monitor | CVE-2016-3952No exploit | web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request web2py · web2py · CWE-255 | High7.8 | — | 1.1% | Feb 6, 2018 |
25Monitor | CVE-2023-22432Proof of concept | Open redirect vulnerability exists in web2py versions prior to 2.23.1.web2py · web2py · CWE-601 | Medium6.1 | — | 2.4% | Mar 5, 2023 |
24Monitor | CVE-2022-33146No exploit | Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and condweb2py · web2py · CWE-601 | Medium6.1 | — | 1.6% | Jun 26, 2022 |
24Monitor | CVE-2015-6961No exploit | Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct web2py · web2py · CWE-601 | Medium6.1 | — | 1.0% | Oct 18, 2017 |
22Monitor | CVE-2016-3954No exploit | web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.web2py · web2py · CWE-200 | Medium5.5 | — | 1.4% | Feb 6, 2018 |
20Monitor | CVE-2016-4807Proof of concept | Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged inweb2py · web2py · CWE-79 | Medium4.8 | — | 2.3% | Jan 11, 2017 |
17Monitor | CVE-2013-2311No exploit | Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attaweb2py · web2py · CWE-79 | Medium4.3 | — | 1.2% | May 22, 2013 |
- CVE-2016-395740Plan
The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, w
CriticalCVSS 9.8Proof of conceptEPSS 5%web2py · web2pyFeb 6, 2018
- CVE-2023-4515840Plan
An OS command injection vulnerability exists in web2py 2.24.1 and earlier.
CriticalCVSS 9.8Proof of conceptEPSS 4%web2py · web2pyOct 16, 2023
- CVE-2016-395340Plan
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a har
CriticalCVSS 9.8No exploitEPSS 3%web2py · web2pyFeb 6, 2018
- CVE-2016-1032140Plan
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-for
CriticalCVSS 9.8No exploitEPSS 3%web2py · web2pyApr 10, 2017
- CVE-2016-480836Monitor
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged
HighCVSS 8.8Proof of conceptEPSS 2%web2py · web2pyJan 11, 2017
- CVE-2016-480633Monitor
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access w
HighCVSS 7.5Proof of conceptEPSS 10%web2py · web2pyJan 11, 2017
- CVE-2016-395231Monitor
web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request
HighCVSS 7.8No exploitEPSS 1%web2py · web2pyFeb 6, 2018
- CVE-2023-2243225Monitor
Open redirect vulnerability exists in web2py versions prior to 2.23.1.
MediumCVSS 6.1Proof of conceptEPSS 2%web2py · web2pyMar 5, 2023
- CVE-2022-3314624Monitor
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and cond
MediumCVSS 6.1No exploitEPSS 2%web2py · web2pyJun 26, 2022
- CVE-2015-696124Monitor
Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct
MediumCVSS 6.1No exploitEPSS 1%web2py · web2pyOct 18, 2017
- CVE-2016-395422Monitor
web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status.
MediumCVSS 5.5No exploitEPSS 1%web2py · web2pyFeb 6, 2018
- CVE-2016-480720Monitor
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in
MediumCVSS 4.8Proof of conceptEPSS 2%web2py · web2pyJan 11, 2017
- CVE-2013-231117Monitor
Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote atta
MediumCVSS 4.3No exploitEPSS 1%web2py · web2pyMay 22, 2013