Archivebox is a self-hosted web archiving and bookmarking application that captures and preserves snapshots of web content, with its known vulnerability profile centered on command and input-handling issues. The durable signal reflects the product's interaction with external tools and browser-rendered content, surfacing recurrent weaknesses in argument injection and cross-site scripting that are characteristic of archive-processing pipelines; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Archivebox over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42601CRITICAL ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets m | May 9, 2026 | 9.8 | 35 | NO | NO |
CVE-2023-45815MEDIUM ArchiveBox is an open source self-hosted web archiving system. Any users who are using the `wget` extractor and view the content it outputs. The impact is potentially severe if you | Oct 19, 2023 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Archivebox.
Media articles that mention a CVE ID that affects a product developed by Archivebox — matched by CVE ID, not by vendor name.