← Back

Crafty Controller

crafty_controller

Vendor: Craftycontrol • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Craftycontrol
1Crafty Controller
Aug 18, 2026
Aug 11, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote cod...Show more
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.Show less
1Craftycontrol
1Crafty Controller
Jun 17, 2026
Apr 21, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.
1Craftycontrol
1Crafty Controller
Jun 17, 2026
Jan 30, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
1Craftycontrol
1Crafty Controller
Jun 17, 2026
Jan 30, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
1Craftycontrol
1Crafty Controller
Jun 17, 2026
Dec 17, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.
1Craftycontrol
1Crafty Controller
Jun 17, 2026
Dec 17, 2025
N/A· v4
9.9 CRITICAL· v3
N/A· v2
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.
1Craftycontrol
1Crafty Controller
Jun 17, 2026
Jun 15, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.
1Craftycontrol
1Crafty Controller
Jun 17, 2026
Feb 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header