Rengine Project maintains a reconnaissance and enumeration platform focused on web application security testing, with a narrow but specialized exposure footprint centered on its flagship Rengine tool. The observed weakness classes—cross-site scripting and OS command injection—reflect the tool's role in parsing and processing untrusted web content and command-line inputs during security assessment workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rengine Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1813CRITICAL OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0. | May 22, 2022 | 9.8 | 25 | NO | NO |
CVE-2021-39491MEDIUM A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . . | Mar 24, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rengine Project.
Media articles that mention a CVE ID that affects a product developed by Rengine Project — matched by CVE ID, not by vendor name.