Csprousers maintains CSWeb, a web-based application whose vulnerability profile centers on information-disclosure and input-handling weaknesses including path traversal, cross-site scripting, and unrestricted file uploads. This vendor profile is compact; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Csprousers over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60947HIGH Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha. | Mar 23, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-60946HIGH Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. | Mar 23, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-60949HIGH Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked | Mar 23, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-60948MEDIUM Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser | Mar 23, 2026 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Csprousers.
Media articles that mention a CVE ID that affects a product developed by Csprousers — matched by CVE ID, not by vendor name.