Craftycontrol maintains a game-server management platform whose vulnerability profile, despite a narrow product scope, skews strongly toward critical-severity outcomes and centers on web-application attack surfaces characteristic of internet-facing control interfaces. The recurring weaknesses cluster around input validation and output encoding failures—path traversal, cross-site scripting, authorization bypass, and HTTP header injection—reflecting the parsing and access-control demands typical of web-based administrative tools. Defenders should prioritize patching this vendor's releases and restrict network exposure of the controller; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Craftycontrol over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14700CRITICAL An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Sid | Dec 17, 2025 | 9.9 | 36 | NO | NO |
CVE-2026-5652CRITICAL An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via i | Apr 21, 2026 | 9.0 | 30 | NO | NO |
CVE-2026-0963HIGH An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remot | Jan 30, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-0805HIGH An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code e | Jan 30, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-14701HIGH An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification | Dec 17, 2025 | 7.1 | 24 | NO | NO |
CVE-2024-1064HIGH A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition vi | Feb 3, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-5990MEDIUM An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via mal | Jun 15, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Craftycontrol.
Media articles that mention a CVE ID that affects a product developed by Craftycontrol — matched by CVE ID, not by vendor name.