Retty's vulnerability profile centers on its restaurant-discovery and reservation platform, with the recurring signal rooted in access-control weaknesses including missing authorization checks and hard-coded credentials. These patterns reflect the authentication and session-management demands of a user-facing web service. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Retty over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20748HIGH Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key for an external service. By exploiting this vulnerability, | Jul 14, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-20747MEDIUM Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a rem | Jul 14, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Retty.
Media articles that mention a CVE ID that affects a product developed by Retty — matched by CVE ID, not by vendor name.