Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Stackstorm

First CVE: Dec 21, 2018Active for: 8 yearsTotal CVEs: 6

Stackstorm is an automation and orchestration platform with a focused vulnerability footprint concentrated in its core product, which serves as a workflow engine for IT operations and security automation. The recurring weakness classes—cross-site scripting, authorization gaps, and logic-flow issues such as infinite loops—reflect the interaction of web-facing interfaces and stateful orchestration logic that characterize this automation platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Stackstorm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2018
7 years ago
Most Recent CVE
Dec 6, 2022
1,326 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44657HIGH
In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode b
Dec 15, 20218.827NONO
CVE-2022-44009HIGH
Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentia
Dec 6, 20227.524NONO
CVE-2021-28667HIGH
StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8,
Mar 18, 20217.523NONO
CVE-2022-43706MEDIUM
Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pack rules to inject arbitrary script or H
Dec 5, 20225.420NONO
CVE-2018-20345MEDIUM
Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackStorm account and is authenticated agains
Dec 21, 20185.320NONO
CVE-2019-9580MEDIUM
In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.
Mar 9, 20196.117NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low3 (50.0%)
High0 (0.0%)
None3 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Stackstorm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Stackstorm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Stackstorm's Products

View all 1 CNAs →

Top CWEs