Statics Server Project maintains a narrowly scoped static file-serving utility with a footprint concentrated in a single product. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Statics Server Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15596HIGH A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory. | Dec 18, 2019 | 7.5 | 22 | NO | NO |
CVE-2018-3771MEDIUM An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser. | Jul 20, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Statics Server Project.
Media articles that mention a CVE ID that affects a product developed by Statics Server Project — matched by CVE ID, not by vendor name.