Ftapi is a modestly represented vendor with a focused vulnerability footprint centered on its web application product, where the durable signal is concentrated in cross-site scripting and input-neutralization issues. Treat this as a compact vendor profile rather than a broad trend; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ftapi over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25277MEDIUM FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component. | Mar 19, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-25278MEDIUM FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template Editor. | Mar 19, 2021 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ftapi.
Media articles that mention a CVE ID that affects a product developed by Ftapi — matched by CVE ID, not by vendor name.