Cutesoft Components maintains a focused line of web-editing components, primarily its Cute Editor and Cute Editor for ASP.NET products, with a durable vulnerability signal centered on web-layer input handling and directory traversal issues. The recurring weakness classes—path traversal and cross-site scripting—reflect the parsing and sanitization demands of server-side HTML editing and file-upload functionality. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cutesoft Components over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4665MEDIUM Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to read arbitrary files via a .. (d | Mar 5, 2010 | 5.0 | 25 | NO | YES |
Cross-site scripting (XSS) vulnerability in InsertDocument.aspx in CuteSoft Cute Editor 6.4 allows remote authenticated users to inject arbitrary web script or HTML via the _Upload | Aug 21, 2012 | 3.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cutesoft Components.
Media articles that mention a CVE ID that affects a product developed by Cutesoft Components — matched by CVE ID, not by vendor name.