Webport's vulnerability profile centers on a narrowly scoped web-application product where disclosures skew toward serious outcomes, with a meaningful share reaching critical severity and a notable tendency toward public exploit availability. The exposure recurs through input-handling and access-control weakness classes including cross-site scripting, path traversal, and SQL injection, reflecting common application-layer validation gaps in web platforms. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webport over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12461MEDIUM Web Port 1.19.1 allows XSS via the /log type parameter. | May 30, 2019 | 6.1 | 43 | NO | YES |
CVE-2019-12460MEDIUM Web Port 1.19.1 allows XSS via the /access/setup type parameter. | May 30, 2019 | 6.1 | 31 | NO | YES |
CVE-2020-18667CRITICAL SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn. | Jun 24, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-18665MEDIUM Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings. | Jun 24, 2021 | 5.3 | 20 | NO | NO |
CVE-2020-18668MEDIUM Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls. | Jun 24, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-18664MEDIUM Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn. | Jun 24, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-23659MEDIUM WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature. | Aug 26, 2020 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webport.
Media articles that mention a CVE ID that affects a product developed by Webport — matched by CVE ID, not by vendor name.