Craws maintains a narrowly scoped portfolio centered on the OpenAtlas product, a platform that despite modest disclosure volume occupies a notable position in the vulnerability landscape. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around application security and configuration weaknesses including cross-site scripting, default and hard-coded credential use, path traversal, and observable discrepancies that are typical of web-facing administrative platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Craws over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-51536CRITICAL Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password. | Aug 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-51535CRITICAL Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability. | Aug 4, 2025 | 9.1 | 29 | NO | NO |
CVE-2025-51534HIGH A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTML via injecting a cra | Aug 4, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-60915HIGH An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted reque | Nov 24, 2025 | 8.1 | 25 | NO | NO |
CVE-2025-40709MEDIUM Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user i | Aug 29, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-40708MEDIUM Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user i | Aug 29, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-40707MEDIUM Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user i | Aug 29, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-40706MEDIUM Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user i | Aug 29, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-40704MEDIUM Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user i | Aug 29, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-60916MEDIUM A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute ar | Nov 24, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Craws.
Media articles that mention a CVE ID that affects a product developed by Craws — matched by CVE ID, not by vendor name.