Sphiderpro maintains a focused search-engine and web-indexing product that, despite a narrow portfolio, presents application-layer attack surface through recurring weaknesses in output neutralization, authentication, and input handling. These vulnerability classes reflect common risks in web-facing query and data-processing applications, where injection, improper authentication, and validation gaps can expose indexed content or allow unauthorized access. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sphiderpro over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5081CRITICAL sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass | Jan 10, 2020 | 9.8 | 45 | NO | YES |
CVE-2014-5087CRITICAL A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code. | Feb 7, 2020 | 9.8 | 44 | NO | YES |
CVE-2014-5086HIGH A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execut | Feb 10, 2020 | 8.8 | 42 | NO | YES |
CVE-2014-5084HIGH A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code. CVE-2014-508 | Feb 10, 2020 | 8.8 | 39 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sphiderpro.
Media articles that mention a CVE ID that affects a product developed by Sphiderpro — matched by CVE ID, not by vendor name.