Rageframe is a web application framework with a narrow product scope where identified vulnerabilities center on input-handling and code-generation weaknesses, particularly cross-site scripting and code injection issues typical of web application codebases. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rageframe over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36530MEDIUM An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page. | Aug 16, 2022 | 6.1 | 24 | NO | NO |
CVE-2024-30879MEDIUM Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a cr | Apr 11, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-30878MEDIUM A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted pa | Apr 11, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-30883MEDIUM Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a cr | Apr 11, 2024 | 4.7 | 16 | NO | NO |
CVE-2024-30880MEDIUM Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a cr | Apr 11, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rageframe.
Media articles that mention a CVE ID that affects a product developed by Rageframe — matched by CVE ID, not by vendor name.