Searchblox is a narrowly scoped enterprise search platform that faces vulnerability exposure concentrated in its core product, presenting an attack surface centered on web-application handling and access control. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through web-layer weakness classes including cross-site scripting, cross-site request forgery, path traversal, and exposure of sensitive information—patterns typical of a Java-based search indexing platform. Defenders should prioritize patching advisories for this product and restrict administrative interface access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Searchblox over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11586CRITICAL XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (S | Jun 5, 2018 | 9.8 | 47 | NO | YES |
CVE-2018-11538HIGH servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass. | Jun 1, 2018 | 8.8 | 42 | NO | YES |
CVE-2015-7919CRITICAL SearchBlox 8.3 before 8.3.1 allows remote attackers to write to the config file, and consequently cause a denial of service (application crash), via unspecified vectors. | Dec 21, 2015 | 10.0 | 41 | NO | NO |
CVE-2020-35580HIGH A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a | May 20, 2021 | 7.5 | 40 | NO | YES |
CVE-2020-10131CRITICAL SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter. | Sep 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-10130HIGH SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system. | Sep 6, 2023 | 8.8 | 25 | NO | NO |
CVE-2015-0968HIGH Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 8.2 allows remote attackers to execute arbitrary code by uploading a file with an executable e | Apr 18, 2015 | 7.5 | 25 | NO | NO |
CVE-2013-3597MEDIUM servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action. | Aug 28, 2013 | 5.0 | 25 | NO | YES |
CVE-2020-10129HIGH SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality. | Sep 6, 2023 | 8.8 | 24 | NO | NO |
CVE-2015-0970HIGH Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users. | Apr 18, 2015 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Searchblox.
Media articles that mention a CVE ID that affects a product developed by Searchblox — matched by CVE ID, not by vendor name.