Webswing is a web-based thin-client and application delivery platform whose vulnerability profile centers on its core product and recurs through path-traversal and injection-class weaknesses typical of web application input handling. Current vulnerability counts, severity distribution, and exploitation status are shown in the live-statistics panel alongside this summary.
The number and severity of CVEs published that impact products developed by Webswing over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34914CRITICAL Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used a | Jul 8, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-39332CRITICAL Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts o | Oct 31, 2024 | 9.8 | 26 | NO | NO |
CVE-2020-11103CRITICAL JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution. | Dec 30, 2020 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webswing.
Media articles that mention a CVE ID that affects a product developed by Webswing — matched by CVE ID, not by vendor name.