Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Spotweb Project

First CVE: Dec 17, 2020Active for: 6 yearsTotal CVEs: 10
41.6
VTI Score
High

Spotweb Project maintains a niche but prominently targeted web-based Usenet client application that has accumulated vulnerabilities skewing toward serious outcomes, with critical-severity instances appearing across its disclosure history. The exposure recurs through application-layer input-handling flaws, chiefly cross-site scripting and SQL injection, which reflect the web-interface architecture and database interaction patterns inherent to the platform; these weakness classes frequently acquire public exploit code. Defenders should treat this vendor's security updates as timely despite its narrow footprint, since the application's web-facing role makes instances in active use attractive targets; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Spotweb Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 17, 2020
5 years ago
Most Recent CVE
Mar 28, 2022
1,579 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35545CRITICAL
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
Dec 17, 20209.832NONO
CVE-2021-43725MEDIUM
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the d
Mar 28, 20226.131NOYES
CVE-2021-40969MEDIUM
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the fi
Oct 1, 20216.130NOYES
CVE-2021-40973MEDIUM
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the la
Oct 1, 20216.129NOYES
CVE-2021-40972MEDIUM
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the ma
Oct 1, 20216.129NOYES
CVE-2021-40971MEDIUM
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the ne
Oct 1, 20216.129NOYES
CVE-2021-40970MEDIUM
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the us
Oct 1, 20216.129NOYES
CVE-2021-40968MEDIUM
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the ne
Oct 1, 20216.129NOYES
CVE-2021-3286CRITICAL
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists becau
Jan 26, 20219.829NONO
CVE-2021-33966MEDIUM
Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.
Jan 21, 20225.419NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
80%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (20.0%)
Unknown0 (0.0%)
Required8 (80.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
7 CVEs
70.0% of CVEs· 99th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Spotweb Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Spotweb Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Spotweb Project's Products

View all 1 CNAs →

Top CWEs