Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Spiceworks

First CVE: Sep 11, 2014Active for: 12 yearsTotal CVEs: 9

Spiceworks develops IT management and helpdesk software deployed across small and mid-sized organizations, and its vulnerability profile skews toward serious outcomes with a strong tendency toward public exploit availability. The recurring weakness classes—cross-site scripting, SQL injection, CSRF, and open redirect—are characteristic of web-facing application input handling and session management, reflecting the browser-accessible nature of its helpdesk and asset-management interfaces. Defenders should prioritize patching for this vendor's server and desktop products given the combination of critical-severity tendency and high exploit-code availability; live exploitation and severity figures are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Spiceworks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2014
11 years ago
Most Recent CVE
Nov 9, 2023
988 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7237CRITICAL
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthent
Apr 6, 20179.844NOYES
CVE-2020-25901MEDIUM
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
Dec 18, 20206.131NOYES
CVE-2012-2956MEDIUM
SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was S
Sep 17, 20146.531NOYES
CVE-2021-43609HIGH
An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/dat
Nov 9, 20238.826NONO
CVE-2012-6658MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, o
Sep 17, 20144.326NOYES
CVE-2020-23451HIGH
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
Sep 15, 20208.824NONO
CVE-2020-23450MEDIUM
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ wit
Sep 1, 20205.421NONO
CVE-2014-3740LOW
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket r
Sep 11, 20143.520NOYES
CVE-2015-6021MEDIUM
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
Apr 10, 20176.117NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
56%
22%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (66.7%)
Unknown3 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (66.7%)
High0 (0.0%)
Unknown3 (33.3%)
User Interaction
None2 (22.2%)
Unknown3 (33.3%)
Required4 (44.4%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None4 (44.4%)
Unknown3 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
55.6% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Spiceworks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Spiceworks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Spiceworks's Products

View all 2 CNAs →

Top CWEs