Maxkey is a niche identity and access management platform whose vulnerability profile centers on server-side request forgery conditions in its core authentication product. The durable signal reflects the web-facing nature of identity infrastructure and the parsing complexity inherent to request handling in authentication workflows. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maxkey over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6517CRITICAL A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dro | Jun 23, 2025 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maxkey.
Media articles that mention a CVE ID that affects a product developed by Maxkey — matched by CVE ID, not by vendor name.