Havenweb maintains a narrowly scoped product portfolio centered on its Haven application, with the observed vulnerability signal concentrated on server-side request forgery weaknesses that can allow attackers to initiate unintended outbound requests from the application. This represents a focused vendor profile rather than a broad trend line; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Havenweb over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24060MEDIUM Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RSS Feeds or add RSS Feeds can su | Jan 27, 2023 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Havenweb.
Media articles that mention a CVE ID that affects a product developed by Havenweb — matched by CVE ID, not by vendor name.