Luckyframe is a test-automation and web-application framework with a concentrated vulnerability footprint centered on its web platform, where the observed weaknesses reflect input-handling and code-integrity risks. The recurring weakness classes—SQL injection, unsafe code downloads, and path traversal—are characteristic of web-application parsers and file-handling logic, and defenders should treat these as priority areas when evaluating or deploying this framework.
The number and severity of CVEs published that impact products developed by Luckyframe over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24221CRITICAL LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml. | Feb 17, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-24220CRITICAL LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml. | Feb 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-24219CRITICAL LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml. | Feb 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-35081HIGH LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method. | May 23, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-33118HIGH LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController. | May 6, 2024 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Luckyframe.
Media articles that mention a CVE ID that affects a product developed by Luckyframe — matched by CVE ID, not by vendor name.