C2pa Web
Vendor:
First CVE: May 12, 2026 · Active for under a year
34
Total CVEs
More Total CVEs than 96% of tracked products
34.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact C2pa Web over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2026
2 months ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
C2pa Web34 CVEs
74%
26%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local27 (79.4%)
Network7 (20.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (97.1%)
High1 (2.9%)
Unknown0 (0.0%)
User Interaction
None30 (88.2%)
Unknown0 (0.0%)
Required4 (11.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None34 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48290HIGH CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attac | Jul 14, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-48352HIGH CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerabilit | Jul 14, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-48351HIGH CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerabilit | Jul 14, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-34711HIGH CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability. An attacker could exploit this vulnerabil | Jun 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-48295HIGH CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage th | Jul 14, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-48287HIGH CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on c | Jul 14, 2026 | 7.4 | 32 | NO | NO |
CVE-2026-34712HIGH CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability t | Jun 9, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-34713HIGH CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnera | Jun 9, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-48312MEDIUM CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to b | Jul 14, 2026 | 6.8 | 30 | NO | NO |
CVE-2026-48357MEDIUM CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerabi | Jul 14, 2026 | 6.2 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (34 CVEs).
Media Mentions
Signals from CVEs in this product scope (34 CVEs).
Top CNAs Publishing CVEs For C2pa Web
Top CWEs
Versions
No cataloged versions.