Softr operates a no-code web application platform that enables users to build business applications from data sources, with its reported vulnerability footprint centered on the platform product itself and characterized by input-handling issues such as cross-site scripting. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softr over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40434CRITICAL Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. | Dec 19, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-48085MEDIUM Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter. | Feb 6, 2023 | 5.4 | 21 | NO | NO |
CVE-2022-32407MEDIUM Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New Account module. This vulnerability allows attack | Oct 27, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softr.
Media articles that mention a CVE ID that affects a product developed by Softr — matched by CVE ID, not by vendor name.