Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Humansignal

First CVE: Nov 9, 2023Active for: 3 yearsTotal CVEs: 11
42.8
VTI Score
High

Humansignal develops data annotation and machine-learning labeling platforms, with its primary exposure centered on Label Studio and its associated ML backend component. The vendor's vulnerability profile reflects the attack surface of web-facing annotation services: cross-site scripting, sensitive information exposure, server-side request forgery, unsafe deserialization, and improper access control recur across its disclosures, indicating input-handling and authentication challenges typical of collaborative web applications. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Humansignal over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 9, 2023
2 years ago
Most Recent CVE
Jan 12, 2026
194 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-47117HIGH
Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering
Nov 13, 20237.534NOYES
CVE-2025-25296MEDIUM
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` re
Feb 14, 20256.132NOYES
CVE-2025-47783MEDIUM
Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a we
May 14, 20256.128NOYES
CVE-2023-47115MEDIUM
Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated u
Jan 23, 20245.427NOYES
CVE-2025-25297HIGH
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerabilit
Feb 14, 20257.723NONO
CVE-2023-43791HIGH
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to im
Nov 9, 20238.822NONO
CVE-2026-22033MEDIUM
Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys fun
Jan 12, 20265.421NONO
CVE-2025-5173HIGH
A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability i
May 26, 20257.821NONO
CVE-2024-26152MEDIUM
### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a [`Choices`](https://label
Feb 22, 20246.118NONO
CVE-2023-47116MEDIUM
Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on version 1.8.2. Label Studio's SSR
Jan 31, 20245.318NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
36%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (45.5%)
Unknown0 (0.0%)
Required6 (54.5%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
36.4% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Humansignal.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Humansignal — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Humansignal's Products

View all 2 CNAs →

Top CWEs