Civetweb is a lightweight, embeddable web server library that appears across embedded systems and applications requiring minimal HTTP functionality, with its vulnerability history centered on a single core product. The durable signal is a pattern of information-disclosure and path-traversal weaknesses, alongside memory-safety issues such as out-of-bounds reads and stack-based buffer overflows, reflecting the parser and file-handling responsibilities of a web server implementation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Civetweb Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27304CRITICAL The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_ha | Oct 21, 2021 | 9.8 | 31 | NO | NO |
CVE-2026-5789HIGH Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malic | Apr 21, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-55763HIGH Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is | Aug 29, 2025 | 7.5 | 25 | NO | NO |
CVE-2018-12684HIGH Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI fi | Jun 22, 2018 | 7.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Civetweb Project.
Media articles that mention a CVE ID that affects a product developed by Civetweb Project — matched by CVE ID, not by vendor name.