Benbusby develops Whoogle Search, a privacy-focused search engine interface that sits between users and upstream search providers, with a niche but security-relevant footprint centered on web-facing request handling. The observed vulnerability classes—server-side request forgery, path traversal, cross-site scripting, and command injection—reflect the product's role in parsing user input, proxying requests, and generating dynamic pages, areas where input sanitization and output encoding are structural requirements. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Benbusby over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-22205CRITICAL Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize user-supplied input from the `location` variable and passes | Jan 23, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-22203CRITICAL Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element | Jan 23, 2024 | 9.8 | 24 | NO | NO |
CVE-2024-53305HIGH An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query. | Apr 16, 2025 | 7.3 | 21 | NO | NO |
CVE-2024-22417MEDIUM Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `elemen | Jan 23, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-22204MEDIUM Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in Whoogle are enabled. The `conf | Jan 23, 2024 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Benbusby.
Media articles that mention a CVE ID that affects a product developed by Benbusby — matched by CVE ID, not by vendor name.