Status maintains a modestly sized portfolio spanning web-application and messaging platforms such as StatusNet, alongside desktop and mobile frameworks, with a prominence in the landscape that reflects their integration into diverse deployments. The vendor's vulnerability profile skews toward serious outcomes, with an elevated share reaching critical severity and a durable pattern of input-handling weaknesses including cross-site scripting, SQL injection, and improper validation that are characteristic of web-facing and user-data processing applications. Live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Status over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4660CRITICAL Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. | Nov 20, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-12164CRITICAL ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution. | Jul 23, 2019 | 9.8 | 30 | NO | NO |
CVE-2010-4659MEDIUM Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents. | Nov 20, 2019 | 6.1 | 22 | NO | NO |
CVE-2011-3370MEDIUM statusnet before 0.9.9 has XSS | Nov 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2010-4658MEDIUM statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks. | Feb 7, 2020 | 5.3 | 20 | NO | NO |
CVE-2013-4137HIGH Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a par | Oct 11, 2013 | 7.5 | 19 | NO | NO |
CVE-2011-3802MEDIUM StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrate | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2023-25780MEDIUM It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vul | Jun 2, 2023 | 5.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Status.
Media articles that mention a CVE ID that affects a product developed by Status — matched by CVE ID, not by vendor name.