csprousers csweb CVE Vulnerabilities (4)

CVEs: 4 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting csprousers csweb (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-60949 Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha. 9119a7d8-5eab-497f-8521-727c672e3725 9.3 0.03% 2026-03-23 2026-03-25
CVE-2025-60948 Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha. 9119a7d8-5eab-497f-8521-727c672e3725 5.1 0.06% 2026-03-23 2026-03-25
CVE-2025-60947 Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha. 9119a7d8-5eab-497f-8521-727c672e3725 8.7 0.36% 2026-03-23 2026-03-25
CVE-2025-60946 Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. 9119a7d8-5eab-497f-8521-727c672e3725 8.7 0.26% 2026-03-23 2026-03-26
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence