Configserver
1 CVEs tracked since 2011. Since Dec 2011, none of them reached CISA KEV.
Configserver CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2011-12 | 1 | 0 |
Products
The products that kept showing up in Configserver's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Configserver.
- CVE-2026-65638Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injectio...—
- CVE-2026-65639OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to...—
- CVE-2026-67402An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is bl...—
- CVE-2011-5033Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (crash) via a long ...4.4
The record
- Peak rank
- #78 in Dec 2011
- Busiest month shown
- Dec 2011, 1 CVEs
- Months with a KEV entry
- 0 since Dec 2011
- Monthly snapshots
- 1 since 2011