Craterapp maintains a niche invoicing and business management application whose vulnerability profile centers on a single product, Crater, serving small to medium business use cases. The recurring exposure reflects typical web application weaknesses: unrestricted file uploads, cross-site request forgery, deserialization of untrusted data, improper access control, and code injection, which arise across the application stack and warrant defensive focus on input handling, authentication boundaries, and file validation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Craterapp over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46865HIGH /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of | Oct 30, 2023 | 7.2 | 31 | NO | NO |
CVE-2021-4080HIGH crater is vulnerable to Unrestricted Upload of File with Dangerous Type | Jan 12, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-1033HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | Mar 23, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-0372MEDIUM Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. | Jan 27, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-1032HIGH Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | Mar 29, 2022 | 7.2 | 19 | NO | NO |
CVE-2022-0242HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. | Jan 17, 2022 | 7.2 | 19 | NO | NO |
CVE-2022-0514MEDIUM Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. | Mar 21, 2022 | 6.5 | 17 | NO | NO |
CVE-2022-0203MEDIUM Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. | Jan 26, 2022 | 5.3 | 16 | NO | NO |
CVE-2022-0515MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. | Mar 21, 2022 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Craterapp.
Media articles that mention a CVE ID that affects a product developed by Craterapp — matched by CVE ID, not by vendor name.