Countly Server

Vendor:

First CVE: May 17, 2022 · Active for 4 years

2
Total CVEs
More Total CVEs than 49% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
8.6
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Countly Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 17, 2022
4 years ago
Most Recent CVE
Feb 20, 2023
1,252 days ago

CVE Severity & Scoring

Countly Server2 CVEs
All CVEs352,719 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (50.0%)
High1 (50.0%)
Unknown0 (0.0%)
User Interaction
None1 (50.0%)
Unknown0 (0.0%)
Required1 (50.0%)
Privileges Required
Low1 (50.0%)
High0 (0.0%)
None1 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (2 CVEs).

2 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edition. The victim must follow a malicious link or be redirect
Feb 20, 20239.027NONO
countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/usernam
May 17, 20228.126NONO

Exploit Exposure

Signals from CVEs in this product scope (2 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (2 CVEs).

Media Mentions

Signals from CVEs in this product scope (2 CVEs).

Top CNAs Publishing CVEs For Countly Server

Top CWEs

Versions

No cataloged versions.