Simplehttpserver Project maintains a lightweight, single-purpose HTTP server utility that is often deployed in development, testing, and ad-hoc file-serving contexts. Its observed vulnerabilities center on path-traversal and cross-site scripting weaknesses, reflecting the challenges of safely implementing request parsing and output encoding in a minimal codebase. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simplehttpserver Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3787HIGH Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server. | Aug 31, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-16478MEDIUM A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root. | Dec 4, 2018 | 5.3 | 20 | NO | NO |
CVE-2018-3716MEDIUM simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. | Jun 7, 2018 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simplehttpserver Project.
Media articles that mention a CVE ID that affects a product developed by Simplehttpserver Project — matched by CVE ID, not by vendor name.