Lansweeper is an IT asset-discovery and inventory-management platform deployed across enterprise networks for visibility into networked devices and software. Vulnerabilities affecting the product skew toward serious outcomes and frequently acquire public exploit code, concentrating in web-application input-handling weaknesses including cross-site scripting, SQL injection, path traversal, and cross-site request forgery that are endemic to web-facing administrative interfaces. Defenders should treat this vendor's security advisories as high-priority given the platform's role in network visibility and the attack surface presented by its web console; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lansweeper over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22149HIGH A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An | Apr 14, 2022 | 8.8 | 67 | NO | NO |
CVE-2022-21234HIGH An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker | Apr 14, 2022 | 8.8 | 67 | NO | NO |
CVE-2022-29517HIGH A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to ar | Dec 15, 2022 | 8.8 | 62 | NO | NO |
CVE-2022-21210HIGH An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacke | Apr 14, 2022 | 8.8 | 60 | NO | NO |
CVE-2022-21145MEDIUM A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrar | Apr 14, 2022 | 4.8 | 58 | NO | NO |
CVE-2020-14011CRITICAL Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allow | Jun 15, 2020 | 9.8 | 52 | NO | YES |
CVE-2019-13462CRITICAL Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. | Aug 12, 2019 | 9.1 | 45 | NO | YES |
CVE-2022-27498MEDIUM A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request | Dec 15, 2022 | 6.5 | 42 | NO | NO |
CVE-2017-13706CRITICAL XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sen | Oct 10, 2017 | 9.9 | 32 | NO | NO |
CVE-2015-9264CRITICAL Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation via a crafted Windows service. | Aug 27, 2018 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lansweeper.
Media articles that mention a CVE ID that affects a product developed by Lansweeper — matched by CVE ID, not by vendor name.