Civetweb
7 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Civetweb, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Civetweb CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High4
- Medium1
Latest CVEs
The 7 most recently published vulnerabilities affecting Civetweb.
- CVE-2026-29035CivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate Decompression6.5
- CVE-2026-5789Search path without quotes in CivetWeb7.8
- CVE-2025-9648Denial of Service in CivetWeb—
- CVE-2025-55763Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during...7.5
- CVE-2020-27304The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request...9.8
- CVE-2019-3821A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exha...7.5
- CVE-2018-12684Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.7.1
Product grouping is registry-driven, with AI assist and human review. How it works