Caldera

Vendor:

First CVE: Mar 22, 2020 · Active for 6 years

12
Total CVEs
More Total CVEs than 90% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Caldera over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 22, 2020
6 years ago
Most Recent CVE
Feb 24, 2025
516 days ago

CVE Severity & Scoring

Caldera12 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (58.3%)
Unknown0 (0.0%)
Required5 (41.7%)
Privileges Required
Low7 (58.3%)
High0 (0.0%)
None5 (41.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the serve
Feb 24, 202510.046NONO
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shel
Jan 12, 20228.837NONO
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe ma
Jan 12, 20228.828NONO
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
Jul 12, 20218.828NONO
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the
Jan 12, 20228.827NONO
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other compo
Jan 12, 20228.126NONO
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.
Oct 17, 20226.122NONO
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.
Oct 17, 20226.122NONO
An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.
Jan 12, 20226.122NONO
CALDERA 2.7.0 allows XSS via the Operation Name box.
Jun 19, 20205.420NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Caldera

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.9.018.82.1%00
2.7.015.40.6%00