Smartfoxserver is a real-time communication and game-server framework whose vulnerability profile centers on the core server product and reflects weaknesses in sensitive data handling and web-layer input processing. The durable signal spans cleartext storage of sensitive information, code injection, and cross-site scripting, pointing to gaps in encryption practices and input sanitization across the platform; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartfoxserver over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26551HIGH An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModule | Feb 9, 2021 | 8.8 | 25 | NO | NO |
CVE-2021-26549MEDIUM An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to ex | Feb 9, 2021 | 5.4 | 18 | NO | NO |
CVE-2021-26550MEDIUM An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml. | Feb 9, 2021 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartfoxserver.
Media articles that mention a CVE ID that affects a product developed by Smartfoxserver — matched by CVE ID, not by vendor name.