The M Server Project maintains a focused server product with a narrow but above-typical presence in tracked vulnerability disclosures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by M Server Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16485MEDIUM Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd by appending slashes | Feb 1, 2019 | 6.5 | 20 | NO | NO |
CVE-2018-16484MEDIUM A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escaping for special characters in folder n | Feb 1, 2019 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by M Server Project.
Media articles that mention a CVE ID that affects a product developed by M Server Project — matched by CVE ID, not by vendor name.