Spyce is a web application framework and server platform whose vulnerability profile centers on input-handling weaknesses spanning improper input validation, path traversal, and cross-site scripting across its core product. These classes reflect the parsing and output-encoding demands characteristic of a web application server; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spyce over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0982MEDIUM Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy, which reveals the path in an | Feb 25, 2008 | 5.8 | 24 | NO | YES |
CVE-2008-0980MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the url or type | Feb 25, 2008 | 4.3 | 23 | NO | YES |
CVE-2008-0981MEDIUM Open redirect vulnerability in spyce/examples/redirect.spy in Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to redirect users to arbitrary web sites and conduct p | Feb 25, 2008 | 6.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spyce.
Media articles that mention a CVE ID that affects a product developed by Spyce — matched by CVE ID, not by vendor name.