Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rws

First CVE: Dec 28, 2005Active for: 21 yearsTotal CVEs: 10
39.8
VTI Score
Medium

RWS maintains a focused portfolio of translation and content-management solutions including WorldServer, MultiTrans, and Statistics Counter that serve publishing and localization workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating across application-layer weaknesses including cross-site scripting, unsafe deserialization, improper access control, and authentication flaws that are characteristic of web-facing business software. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rws over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2005
20 years ago
Most Recent CVE
Nov 18, 2024
613 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-34267CRITICAL
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploade
Dec 25, 20239.862NOYES
CVE-2023-38357MEDIUM
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.
Aug 1, 20235.329NOYES
CVE-2022-34268CRITICAL
An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.
Dec 25, 20239.827NONO
CVE-2022-34270CRITICAL
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.
Feb 29, 20249.825NONO
CVE-2022-34269HIGH
An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the
Feb 29, 20248.825NONO
CVE-2024-50848MEDIUM
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arb
Nov 18, 20246.519NONO
CVE-2005-4548HIGH
SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
Dec 28, 20057.519NONO
CVE-2024-43025MEDIUM
An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted payload in
Sep 18, 20246.118NONO
CVE-2024-43024MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload
Sep 18, 20246.118NONO
CVE-2024-50849MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker to execute arbitrary JavaScript code.
Nov 18, 20244.816NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
50%
20%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (90.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None5 (50.0%)
Unknown1 (10.0%)
Required4 (40.0%)
Privileges Required
Low1 (10.0%)
High1 (10.0%)
None7 (70.0%)
Unknown1 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 96th percentile
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rws.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rws — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rws's Products

View all 1 CNAs →

Top CWEs