Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yaws

First CVE: Jun 17, 2005Active for: 21 yearsTotal CVEs: 11
38.9
VTI Score
Medium

Yaws is a lightweight open-source web server with a modestly represented but prominent vulnerability footprint, where disclosed flaws skew toward serious severity outcomes and frequently acquire public exploit code. The exposure centers on the core webserver product and recurs through input-handling and access-control weakness classes—path traversal, improper input validation, cross-site scripting, OS command injection, and XML external entity reference flaws—that are characteristic of web-facing services processing untrusted data. Defenders should treat Yaws instances as patching targets, particularly when exposed to the network; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yaws over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2005
21 years ago
Most Recent CVE
Sep 9, 2020
2,144 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-10974HIGH
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defe
Jul 7, 20177.579NOYES
CVE-2020-24916CRITICAL
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
Sep 9, 20209.838NONO
CVE-2011-4350MEDIUM
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files
Nov 26, 20196.538NOYES
CVE-2020-24379CRITICAL
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
Sep 9, 20209.832NONO
CVE-2010-4181MEDIUM
Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences.
Nov 4, 20105.030NOYES
CVE-2009-0751MEDIUM
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.
Mar 2, 20095.029NOYES
CVE-2011-5025MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to
Dec 29, 20114.326NOYES
CVE-2009-4495MEDIUM
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary comman
Jan 13, 20105.026NOYES
CVE-2020-12872MEDIUM
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with
May 15, 20205.520NONO
CVE-2016-1000108MEDIUM
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data
Dec 10, 20196.120NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
73%
9%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network5 (45.5%)
Unknown5 (45.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (54.5%)
High0 (0.0%)
Unknown5 (45.5%)
User Interaction
None5 (45.5%)
Unknown5 (45.5%)
Required1 (9.1%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None4 (36.4%)
Unknown5 (45.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
5 CVEs
45.5% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yaws.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yaws — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yaws's Products

View all 2 CNAs →

Top CWEs