Stefanprodan maintains a narrowly scoped portfolio centered on the Podinfo project, a lightweight Kubernetes demonstration and testing application widely used for container orchestration examples and deployment validation. The observed vulnerabilities cluster around web-layer input handling, specifically cross-site scripting and unrestricted file upload issues that are characteristic of demo applications exposed to untrusted input. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stefanprodan over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43644MEDIUM podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to th | May 14, 2026 | 6.1 | 25 | NO | NO |
CVE-2025-70849MEDIUM Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uplo | Feb 3, 2026 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stefanprodan.
Media articles that mention a CVE ID that affects a product developed by Stefanprodan — matched by CVE ID, not by vendor name.