Count maintains Countly Server, an analytics platform that collects and processes event data from web and mobile applications. Its observed vulnerability profile centers on application-layer weaknesses including cross-site scripting in page generation and weak password-recovery mechanisms, reflecting risks common to web-facing data-collection services. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Count over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32852CRITICAL Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edition. The victim must follow a malicious link or be redirect | Feb 20, 2023 | 9.0 | 27 | NO | NO |
CVE-2022-29174HIGH countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/usernam | May 17, 2022 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Count.
Media articles that mention a CVE ID that affects a product developed by Count — matched by CVE ID, not by vendor name.