CPAN hosts a modestly represented collection of open-source Perl modules that, despite a narrow product scope, reach into diverse downstream applications and build pipelines where Perl remains embedded. The vulnerabilities affecting this repository skew toward serious outcomes, clustering around file-handling and command-injection weaknesses—link-following flaws and improper neutralization of shell metacharacters—that are characteristic of scripting-language libraries where input validation and file-access boundaries require careful implementation. Defenders should inventory Perl dependencies in their supply chains and treat updates to widely used CPAN modules as components requiring review; current severity, exploitation, and coverage details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cpan over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7315CRITICAL UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands. | Oct 10, 2017 | 9.8 | 32 | NO | NO |
CVE-2011-4117HIGH The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files. | Jan 31, 2020 | 7.5 | 25 | NO | NO |
CVE-2011-4115HIGH Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files. | Jan 31, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-16155MEDIUM The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data. | Dec 13, 2021 | 6.5 | 23 | NO | NO |
CVE-2004-2332MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in CPAN WWW::Form before 1.13 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. | Dec 31, 2004 | 4.3 | 18 | NO | NO |
_is_safe in the File::Temp module for Perl does not properly handle symlinks. | Jan 31, 2020 | 3.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpan.
Media articles that mention a CVE ID that affects a product developed by Cpan — matched by CVE ID, not by vendor name.