Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dradisframework

First CVE: Mar 12, 2019Active for: 7 yearsTotal CVEs: 6

Dradisframework maintains a specialized vulnerability-disclosure and collaboration platform used by security teams, with a narrowly scoped product footprint centered on the Dradis application itself. The recurring vulnerability signal reflects the platform's role as a web-facing, multi-user system: weaknesses cluster around input-handling and output-encoding issues such as cross-site scripting, authentication and authorization bypass conditions, race conditions in shared resource access, and sensitive information exposure through metadata. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.3
Avg CVSS Score
Higher Avg CVSS Score than 15% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dradisframework over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2019
7 years ago
Most Recent CVE
Jul 10, 2025
379 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-30028MEDIUM
Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.
Jun 24, 20225.921NONO
CVE-2023-31223MEDIUM
Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
Apr 25, 20235.420NONO
CVE-2019-19946MEDIUM
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
Mar 16, 20206.520NONO
CVE-2019-5925MEDIUM
Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authentica
Mar 12, 20195.420NONO
CVE-2023-50458MEDIUM
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
Jul 10, 20254.315NONO
CVE-2023-50786MEDIUM
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized au
Jul 5, 20254.315NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low5 (83.3%)
High0 (0.0%)
None1 (16.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dradisframework.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dradisframework — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dradisframework's Products

View all 2 CNAs →

Top CWEs