Serve Lite Project maintains a lightweight web server, with a narrow but notable product scope that reflects its focused role in simple static-content delivery and embedded use cases. The project's disclosure history centers on its single core product with no clearly recurrent weakness pattern emerging, presenting a compact vendor profile where live severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Serve Lite Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21192HIGH All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is | Jan 26, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-25847MEDIUM All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its conten | Jan 26, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Serve Lite Project.
Media articles that mention a CVE ID that affects a product developed by Serve Lite Project — matched by CVE ID, not by vendor name.