Spiceworks develops IT management and helpdesk software deployed across small and mid-sized organizations, and its vulnerability profile skews toward serious outcomes with a strong tendency toward public exploit availability. The recurring weakness classes—cross-site scripting, SQL injection, CSRF, and open redirect—are characteristic of web-facing application input handling and session management, reflecting the browser-accessible nature of its helpdesk and asset-management interfaces. Defenders should prioritize patching for this vendor's server and desktop products given the combination of critical-severity tendency and high exploit-code availability; live exploitation and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spiceworks over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7237CRITICAL The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthent | Apr 6, 2017 | 9.8 | 44 | NO | YES |
CVE-2020-25901MEDIUM Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages. | Dec 18, 2020 | 6.1 | 31 | NO | YES |
CVE-2012-2956MEDIUM SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was S | Sep 17, 2014 | 6.5 | 31 | NO | YES |
CVE-2021-43609HIGH An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/dat | Nov 9, 2023 | 8.8 | 26 | NO | NO |
CVE-2012-6658MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, o | Sep 17, 2014 | 4.3 | 26 | NO | YES |
CVE-2020-23451HIGH Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function. | Sep 15, 2020 | 8.8 | 24 | NO | NO |
CVE-2020-23450MEDIUM Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ wit | Sep 1, 2020 | 5.4 | 21 | NO | NO |
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket r | Sep 11, 2014 | 3.5 | 20 | NO | YES |
CVE-2015-6021MEDIUM Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response. | Apr 10, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spiceworks.
Media articles that mention a CVE ID that affects a product developed by Spiceworks — matched by CVE ID, not by vendor name.