Yogeshojha maintains rengine, a reconnaissance and vulnerability-scanning platform widely adopted in security testing and bug-bounty workflows, where its vulnerability footprint centers on web-application attack surface issues. The vendor's disclosures skew toward serious outcomes and show a moderate tendency toward public exploit availability, with recurring weaknesses in input validation (cross-site scripting), OS command injection, access control, and sensitive-information exposure that are characteristic of tools bridging user-supplied reconnaissance data and system command execution. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yogeshojha over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50094HIGH reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The comma | Jan 1, 2024 | 8.8 | 41 | NO | YES |
CVE-2022-36566CRITICAL Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function. | Aug 31, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-28995CRITICAL Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function. | May 20, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-38606CRITICAL reNgine through 0.5 relies on a predictable directory name. | Aug 12, 2021 | 9.8 | 31 | NO | NO |
CVE-2024-58287HIGH reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. A | Dec 11, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-24968HIGH reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tes | Feb 4, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-24962HIGH reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in | Feb 3, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-61319MEDIUM ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized pay | Oct 10, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-24899HIGH reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Pene | Feb 3, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-24967MEDIUM reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. | Feb 4, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yogeshojha.
Media articles that mention a CVE ID that affects a product developed by Yogeshojha — matched by CVE ID, not by vendor name.