Lastyard's vulnerability footprint centers on its Last Yard product and reflects a pattern of data-protection weaknesses: cleartext transmission of sensitive information, missing encryption of sensitive data, and permissive cross-domain security policies. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lastyard over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47714CRITICAL Last Yard 22.09.8-1 does not enforce HSTS headers | Feb 1, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-47717HIGH Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS). | Feb 1, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-47715MEDIUM In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic. | Feb 1, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lastyard.
Media articles that mention a CVE ID that affects a product developed by Lastyard — matched by CVE ID, not by vendor name.