Ssssssss develops a focused set of low-code and workflow automation products, particularly Spider-Flow and Magic-API, that serve as data-processing and API-integration platforms. The observed vulnerability signal concentrates on code-injection and untrusted-deserialization weaknesses, reflecting the inherent risks of dynamic code execution and data handling in automation frameworks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ssssssss over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0195CRITICAL A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file src/main/java/org/spiderflow/co | Jan 2, 2024 | 9.8 | 50 | NO | YES |
CVE-2023-5016CRITICAL A vulnerability was found in spider-flow up to 0.5.0. It has been declared as critical. Affected by this vulnerability is the function DriverManager.getConnection of the file src/m | Sep 17, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-0196HIGH A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resource/file/api/save?a | Jan 2, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ssssssss.
Media articles that mention a CVE ID that affects a product developed by Ssssssss — matched by CVE ID, not by vendor name.