Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Searchblox

First CVE: Aug 28, 2013Active for: 13 yearsTotal CVEs: 17
55.7
VTI Score
TOP TARGET

Searchblox is a narrowly scoped enterprise search platform that faces vulnerability exposure concentrated in its core product, presenting an attack surface centered on web-application handling and access control. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through web-layer weakness classes including cross-site scripting, cross-site request forgery, path traversal, and exposure of sensitive information—patterns typical of a Java-based search indexing platform. Defenders should prioritize patching advisories for this product and restrict administrative interface access; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Searchblox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 28, 2013
12 years ago
Most Recent CVE
Sep 6, 2023
1,052 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-11586CRITICAL
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (S
Jun 5, 20189.847NOYES
CVE-2018-11538HIGH
servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.
Jun 1, 20188.842NOYES
CVE-2015-7919CRITICAL
SearchBlox 8.3 before 8.3.1 allows remote attackers to write to the config file, and consequently cause a denial of service (application crash), via unspecified vectors.
Dec 21, 201510.041NONO
CVE-2020-35580HIGH
A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a
May 20, 20217.540NOYES
CVE-2020-10131CRITICAL
SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.
Sep 6, 20239.830NONO
CVE-2020-10130HIGH
SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system.
Sep 6, 20238.825NONO
CVE-2015-0968HIGH
Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 8.2 allows remote attackers to execute arbitrary code by uploading a file with an executable e
Apr 18, 20157.525NONO
CVE-2013-3597MEDIUM
servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action.
Aug 28, 20135.025NOYES
CVE-2020-10129HIGH
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality.
Sep 6, 20238.824NONO
CVE-2015-0970HIGH
Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users.
Apr 18, 20158.822NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
47%
35%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (58.8%)
Unknown7 (41.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (58.8%)
High0 (0.0%)
Unknown7 (41.2%)
User Interaction
None6 (35.3%)
Unknown7 (41.2%)
Required4 (23.5%)
Privileges Required
Low3 (17.6%)
High0 (0.0%)
None7 (41.2%)
Unknown7 (41.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.9% of CVEs· 96th percentile
ExploitDB
3 CVEs
17.6% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Searchblox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Searchblox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Searchblox's Products

View all 3 CNAs →

Top CWEs