Antsword Project maintains a web shell management tool designed for penetration testing and post-exploitation scenarios, with the identified vulnerability surface centered on its core Antsword product. The recurring exposure reflects input-handling weaknesses, specifically cross-site scripting conditions that arise in web-facing components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Antsword Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-18766CRITICAL A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands. | Oct 26, 2020 | 9.6 | 29 | NO | NO |
CVE-2020-25470MEDIUM AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can | Oct 26, 2020 | 6.1 | 21 | NO | NO |
CVE-2019-13970MEDIUM In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index | Jul 19, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Antsword Project.
Media articles that mention a CVE ID that affects a product developed by Antsword Project — matched by CVE ID, not by vendor name.