Exif's vulnerability profile centers on its image-metadata handling product, with the observed signal rooted in web-facing input-processing weaknesses, notably cross-site scripting flaws arising from improper neutralization of user-supplied data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exif over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1501MEDIUM Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arb | May 1, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exif.
Media articles that mention a CVE ID that affects a product developed by Exif — matched by CVE ID, not by vendor name.