Crafty Controller
Vendor:
First CVE: Feb 3, 2024 · Active for 2 years
7
Total CVEs
More Total CVEs than 83% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Crafty Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2024
2 years ago
Most Recent CVE
Apr 21, 2026
95 days ago
CVE Severity & Scoring
Crafty Controller7 CVEs
14%
57%
29%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low4 (57.1%)
High1 (14.3%)
None2 (28.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14700CRITICAL An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Sid | Dec 17, 2025 | 9.9 | 36 | NO | NO |
CVE-2026-5652CRITICAL An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via i | Apr 21, 2026 | 9.0 | 30 | NO | NO |
CVE-2026-0963HIGH An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remot | Jan 30, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-0805HIGH An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code e | Jan 30, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-14701HIGH An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification | Dec 17, 2025 | 7.1 | 24 | NO | NO |
CVE-2024-1064HIGH A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition vi | Feb 3, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-5990MEDIUM An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via mal | Jun 15, 2025 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Crafty Controller
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.7.0 | 1 | 8.8 | 0.7% | 0 | 0 |
| 4.6.1 | 1 | 9.9 | 6.1% | 0 | 0 |
| 4.2.0 | 1 | 5.4 | 0.2% | 0 | 0 |