Droppy Project maintains a lightweight file-sharing and cloud-storage application with a modest vulnerability footprint centered on its core Droppy product and web-application input handling. The durable signal reflects common web-tier weaknesses: cross-site request forgery and path-traversal issues that arise in the product's file-access and session-management architecture. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Droppy Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10529HIGH Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the con | May 31, 2018 | 8.8 | 25 | NO | NO |
CVE-2020-7757MEDIUM This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server. | Nov 2, 2020 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Droppy Project.
Media articles that mention a CVE ID that affects a product developed by Droppy Project — matched by CVE ID, not by vendor name.