Liveconfig is a hosting control panel and server management platform whose vulnerability exposure centers on web-based administrative interfaces and the path-handling and input-validation demands they entail. The observed weakness classes—path traversal and cross-site scripting—reflect typical application-layer risks in web management tools where improper canonicalization and output encoding can grant unauthorized file access or session compromise. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liveconfig over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40841MEDIUM A Path Traversal vulnerability for a log file in LiveConfig 2.12.2 allows authenticated attackers to read files on the underlying server. | Feb 18, 2022 | 6.5 | 22 | NO | NO |
CVE-2024-22851HIGH Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint. | Feb 2, 2024 | 7.5 | 21 | NO | NO |
CVE-2021-40840MEDIUM A Stored XSS issue exists in the admin/users user administration form in LiveConfig 2.12.2. | Feb 18, 2022 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liveconfig.
Media articles that mention a CVE ID that affects a product developed by Liveconfig — matched by CVE ID, not by vendor name.