Embedthis maintains a narrow but strategically positioned product line centered on lightweight embedded web servers and application frameworks, particularly GoAhead and AppWeb, that are deployed across networked appliances, IoT devices, and edge systems where footprint and resource constraints drive adoption. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting both the memory-safety challenges of embedded C codebases and the high value of compromising internet-facing appliances. The exposure recurs through a durable set of weakness classes—NULL-pointer dereferences, authentication bypasses via capture-replay, improper access control, code injection, and information disclosure—that together characterize the authentication and input-handling demands of embedded web interfaces. Because these products are often compiled into firmware and deployed across long product lifecycles with infrequent patching, a single vulnerability can remain exploitable across millions of installed devices for years. Defenders should prioritize inventory of Embedthis-based appliances, restrict management exposure, and treat this vendor's security advisories as high-impact despite the modest product count; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Embedthis over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17562HIGH Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CG | Dec 12, 2017 | 8.1 | 98 | YES | YES |
CVE-2019-5096CRITICAL An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and | Dec 3, 2019 | 9.8 | 68 | NO | NO |
CVE-2021-42342CRITICAL An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. | Oct 14, 2021 | 9.8 | 63 | NO | NO |
CVE-2018-8715HIGH The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible | Mar 15, 2018 | 8.1 | 49 | NO | YES |
CVE-2019-5097HIGH A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A spe | Dec 3, 2019 | 7.5 | 48 | NO | NO |
CVE-2017-5674CRITICAL A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.i | Mar 13, 2017 | 9.8 | 42 | NO | NO |
CVE-2014-9708MEDIUM Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demons | Mar 31, 2015 | 5.0 | 42 | NO | NO |
CVE-2014-9707HIGH EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a | Mar 31, 2015 | 7.5 | 42 | NO | YES |
CVE-2019-16645HIGH An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary H | Sep 20, 2019 | 8.6 | 41 | NO | YES |
CVE-2017-1000471CRITICAL EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service. | Jan 3, 2018 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Embedthis.
Media articles that mention a CVE ID that affects a product developed by Embedthis — matched by CVE ID, not by vendor name.