Wtfutil is a personal-information and status-display dashboard tool with a narrow, developer-focused deployment footprint. The vendor's vulnerability profile centers on its core wtf product and recurs around incorrect default-permission issues that can expose local configuration and data to unintended access. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wtfutil over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15716MEDIUM WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or | Aug 28, 2019 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wtfutil.
Media articles that mention a CVE ID that affects a product developed by Wtfutil — matched by CVE ID, not by vendor name.