Safe's vulnerability footprint centers on FME Server, a data-integration and ETL platform widely deployed in business analytics and geospatial workflows, with the recurring exposure rooted in web-facing input handling and configuration management. The durable signal reflects the product's role processing untrusted data and generating dynamic content: vulnerabilities cluster around cross-site scripting, path traversal, XML external entity injection, and insecure defaults that are endemic to platforms bridging user input, file systems, and markup generation. Current severity, exploitation, and disclosure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Safe over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20402HIGH Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account. The passwords to the three accounts are the | Dec 23, 2018 | 8.8 | 26 | NO | NO |
CVE-2022-38340HIGH Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload. | Sep 20, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-38341HIGH Safe Software FME Server v2021.2.5 and below does not employ server-side validation. | Sep 19, 2022 | 7.1 | 24 | NO | NO |
CVE-2023-35801HIGH A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting | Jun 23, 2023 | 8.1 | 23 | NO | NO |
CVE-2022-38339MEDIUM Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a | Sep 19, 2022 | 6.1 | 23 | NO | NO |
CVE-2020-22789MEDIUM Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login p | Apr 28, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-22790MEDIUM Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of t | Apr 28, 2021 | 5.4 | 19 | NO | NO |
CVE-2022-38342MEDIUM Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data e | Sep 13, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Safe.
Media articles that mention a CVE ID that affects a product developed by Safe — matched by CVE ID, not by vendor name.