Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nette

First CVE: Oct 1, 2020Active for: 6 yearsTotal CVEs: 3

Nette is a lightweight, modestly represented PHP framework and templating engine (Latte) used for web application development, where its vulnerability footprint clusters around template and input-handling weaknesses. The recurring exposure centers on code injection, cross-site scripting, injection flaws, and authorization bypasses that reflect the framework's role in processing user-supplied content and controlling access to application features. Live severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
3
Total CVEs
More Total CVEs than 72% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nette over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2020
5 years ago
Most Recent CVE
Jan 4, 2022
1,662 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-15227CRITICAL
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leadi
Oct 1, 20209.862NOYES
CVE-2021-23803CRITICAL
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disa
Dec 17, 20219.828NONO
CVE-2022-21648MEDIUM
Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists
Jan 4, 20226.122NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (66.7%)
Unknown0 (0.0%)
Required1 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
33.3% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nette.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nette — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nette's Products

View all 2 CNAs →

Top CWEs