Carrental Project maintains a narrowly scoped vehicle rental management application with a durable vulnerability pattern centered on information-exposure and authentication weaknesses: files or directories accessible to external parties, hard-coded credentials, and hard-coded passwords recur across its disclosures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Carrental Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9310HIGH A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. Affected by this vulnerability is an unknown functionality of the file /carRental | Aug 21, 2025 | 7.5 | 24 | NO | NO |
CVE-2023-33517HIGH carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System). | Oct 23, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Carrental Project.
Media articles that mention a CVE ID that affects a product developed by Carrental Project — matched by CVE ID, not by vendor name.