Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sonatype Inc.

First CVE: Jan 17, 2014Active for: 13 yearsTotal CVEs: 46
59.9
VTI Score
TOP TARGET

Sonatype Inc. develops a focused line of software supply-chain and repository-management products, primarily Nexus Repository Manager and Nexus IQ Server, that occupy a critical but specialized position in build and artifact-distribution pipelines across enterprise development environments. The vendor's vulnerability footprint, while limited in product breadth, appears among the more prominent in the landscape due to the depth and prevalence of these tools in continuous-integration infrastructure. Recurring exposure centers on web-application and access-control flaws—cross-site scripting, path traversal, expression-language injection, and authorization weaknesses—that reflect the complexity of repository parsing, plugin execution, and user-privilege management in a platform that handles both privileged build operations and external artifact sources. A meaningful share of vulnerabilities affecting this vendor reach serious severity, and defenders should treat disclosures for these products as high-priority because remediation delays create supply-chain ingress points. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
4.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sonatype Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2014
12 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Self-Reporting Analysis

Of all the CVEs published by Sonatype Inc. as a CNA, 13.8% affect products that Sonatype Inc. develops as a vendor.

13.8%
86.2%
Self-reported: 4 (13.8%)
Third-party: 25 (86.2%)

Of all the CVEs published that affect products developed by Sonatype Inc., 8.7% are self-published by Sonatype Inc. as a CNA.

91.3%
Self-published: 4 (8.7%)
Other CNAs: 42 (91.3%)

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-10199HIGH
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Apr 1, 20208.898YESYES
CVE-2019-7238CRITICAL
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
Mar 21, 20199.895YESYES
CVE-2019-5475HIGH
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configurati
Sep 3, 20198.837NONO
CVE-2020-10204HIGH
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
Apr 1, 20207.236NONO
CVE-2026-11403HIGH
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targ
Jul 14, 20268.735NONO
CVE-2021-37152MEDIUM
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to
Aug 10, 20215.430NONO
CVE-2020-15012HIGH
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get acces
Oct 12, 20208.629NONO
CVE-2017-17717CRITICAL
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.
Dec 17, 20179.829NONO
CVE-2026-3329HIGH
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
Jun 11, 20267.528NONO
CVE-2021-40143HIGH
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information o
Sep 7, 20218.226NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
50%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network43 (93.5%)
Unknown3 (6.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (93.5%)
High0 (0.0%)
Unknown3 (6.5%)
User Interaction
None30 (65.2%)
Unknown3 (6.5%)
Required13 (28.3%)
Privileges Required
Low10 (21.7%)
High13 (28.3%)
None20 (43.5%)
Unknown3 (6.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
2 CVEs
4.3% of CVEs· 99th percentile
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
2 CVEs
4.3% of CVEs· 95th percentile
ExploitDB
1 CVE
2.2% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sonatype Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sonatype Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sonatype Inc.'s Products

View all 3 CNAs →

Top CWEs