Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

W3

First CVE: Jan 28, 2009Active for: 17 yearsTotal CVEs: 8

W3 maintains a modestly represented portfolio of web standards reference implementations and validators—including the Amaya browser, CSS Validator, and EPUB checking tools—that collectively serve as conformance and parsing infrastructure across the web platform ecosystem. The vulnerability exposure centers on input-handling and parsing logic, recurring through cross-site scripting, buffer boundary issues, XML external entity references, and infinite-loop conditions endemic to validators and document processors. Public exploit code has frequently been made available for this vendor's vulnerabilities, consistent with the accessibility and tooling nature of these reference implementations; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by W3 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 28, 2009
17 years ago
Most Recent CVE
Mar 28, 2025
483 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-0323HIGH
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which i
Jan 28, 200910.078NOYES
CVE-2009-1209HIGH
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.
Apr 1, 20099.340NOYES
CVE-2025-1781MEDIUM
There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF).  This c
Mar 28, 20256.520NONO
CVE-2023-30300MEDIUM
An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.
May 3, 20235.520NONO
CVE-2016-9487HIGH
EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a specially crafted EPUB file may
Jul 13, 20187.820NONO
CVE-2014-125108MEDIUM
A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue affects some unknown processing of the file spellchecker. The m
Dec 23, 20236.118NONO
CVE-2021-4296MEDIUM
A vulnerability, which was classified as problematic, has been found in w3c Unicorn. This issue affects the function ValidatorNuMessage of the file src/org/w3c/unicorn/response/imp
Dec 29, 20226.118NONO
CVE-2017-5928LOW
The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach
Feb 27, 20173.713NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
13%
50%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (25.0%)
Network4 (50.0%)
Unknown2 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High1 (12.5%)
Unknown2 (25.0%)
User Interaction
None2 (25.0%)
Unknown2 (25.0%)
Required4 (50.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None5 (62.5%)
Unknown2 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
12.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by W3.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by W3 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For W3's Products

View all 4 CNAs →

Top CWEs