Dancer is a lightweight, open-source web framework for Perl that provides request routing and handler functionality for web applications. The framework's observed vulnerability profile centers on improper input validation, reflecting the data-handling attack surface inherent to web request processing. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dancer over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1010084MEDIUM Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unathorised access to data. The component is: Incorrect calls to | Jul 17, 2019 | 6.5 | 21 | NO | NO |
CVE-2012-5572MEDIUM CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response | May 30, 2014 | 5.0 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dancer.
Media articles that mention a CVE ID that affects a product developed by Dancer — matched by CVE ID, not by vendor name.