Craftycontrol
Craftycontrol Crafty Controller: vulnerabilidades y CVE
Craftycontrol Crafty Controller tiene 8 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses6
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13716 | Crítica (9.1) | 0.80% | — | 11 ago 2026 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote… |
| CVE-2026-5652 | Crítica (9) | 0.51% | — | 21 abr 2026 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation. |
| CVE-2026-0963 | Alta (8.8) | 0.75% | — | 30 ene 2026 | An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. |
| CVE-2026-0805 | Alta (8.8) | 0.66% | — | 30 ene 2026 | An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. |
| CVE-2025-14701 | Alta (7.1) | 0.29% | — | 17 dic 2025 | An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification. |
| CVE-2025-14700 | Crítica (9.9) | 6.6% | — | 17 dic 2025 | An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection. |
| CVE-2025-5990 | Media (5.4) | 0.26% | — | 15 jun 2025 | An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input. |
| CVE-2024-1064 | Alta (7.5) | 0.81% | — | 3 feb 2024 | A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.