Streampark
Vendor:
First CVE: May 1, 2023 · Active for 3 years
17
Total CVEs
More Total CVEs than 93% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Streampark over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2023
3 years ago
Most Recent CVE
Dec 12, 2025
224 days ago
CVE Severity & Scoring
Streampark17 CVEs
41%
35%
24%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.9%)
Network16 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (94.1%)
High1 (5.9%)
Unknown0 (0.0%)
User Interaction
None16 (94.1%)
Unknown0 (0.0%)
Required1 (5.9%)
Privileges Required
Low4 (23.5%)
High4 (23.5%)
None9 (52.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54947CRITICAL In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, | Dec 12, 2025 | 9.8 | 32 | NO | NO |
CVE-2022-45802CRITICAL Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may | May 1, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-46365CRITICAL Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whe | May 1, 2023 | 9.1 | 29 | NO | NO |
CVE-2024-29178HIGH On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the | Jul 18, 2024 | 8.8 | 26 | NO | NO |
CVE-2025-54981HIGH Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have riske | Dec 12, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-30001HIGH Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark.
This issue affects Apache StreamPark: from 2.1.4 before 2.1.6.
Users are recommended to upgrade to ve | Oct 10, 2025 | 7.3 | 25 | NO | NO |
CVE-2024-48988HIGH SQL Injection vulnerability in Apache StreamPark.
This issue affects Apache StreamPark: from 2.1.4 before 2.1.6.
Users are recommended to upgrade to version 2.1.6, which fixes th | Aug 22, 2025 | 7.6 | 25 | NO | NO |
CVE-2024-29070CRITICAL On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication | Jul 23, 2024 | 9.1 | 25 | NO | NO |
CVE-2023-52290HIGH In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generat | Jul 16, 2024 | 8.1 | 23 | NO | NO |
CVE-2025-53960MEDIUM When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An attacker can exploit this vulne | Dec 12, 2025 | 5.9 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Streampark
Top CWEs
Versions
No cataloged versions.