Usvn is a web-based version-control system centered around a single user-friendly Subversion product that operates as a centralized repository interface. Its vulnerability profile reflects the attack surface of a web application handling repository access and user authentication, with recurring weaknesses in cross-site scripting, cross-site request forgery, OS command injection, and input validation that are typical of web-facing administrative tools. Vulnerabilities affecting this vendor skew strongly toward critical severity; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usvn over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17363CRITICAL USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredre | Dec 31, 2020 | 9.9 | 31 | NO | NO |
CVE-2020-25069CRITICAL USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view. | Sep 1, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-25070HIGH USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature. | Sep 1, 2020 | 8.8 | 26 | NO | NO |
CVE-2018-0695MEDIUM Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Nov 15, 2018 | 6.1 | 21 | NO | NO |
CVE-2020-17364MEDIUM USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs. | Aug 5, 2020 | 6.1 | 17 | NO | NO |
CVE-2014-4719MEDIUM Cross-site scripting (XSS) vulnerability in the login panel (svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 allows remote attackers to inject arbitrary web script or HTML | Jul 3, 2014 | 4.3 | 17 | NO | NO |
CVE-2007-5945MEDIUM USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors. | Nov 14, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usvn.
Media articles that mention a CVE ID that affects a product developed by Usvn — matched by CVE ID, not by vendor name.