Remark42 is a focused, self-hosted comment system product that exposes a web application interface vulnerable to input-handling flaws, with the observed weakness classes centered on cross-site scripting and server-side request forgery. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Remark42 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45966HIGH umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability. | Oct 23, 2023 | 7.5 | 22 | NO | NO |
CVE-2021-29271MEDIUM remark42 before 1.6.1 allows XSS, as demonstrated by "Locator: Locator{URL:" followed by an XSS payload. This is related to backend/app/store/comment.go and backend/app/store/servi | Mar 27, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Remark42.
Media articles that mention a CVE ID that affects a product developed by Remark42 — matched by CVE ID, not by vendor name.