Embedthis / Goahead
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-53155 | goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter. | HIGH | 7.2 | Jul 25, 2025 |
| CVE-2024-3187 | This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.0.0. These are caused by JST values not… | MEDIUM | 5.9 | Oct 17, 2024 |
| CVE-2024-3186 | CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when compiled with the ME_GOAHEAD_JAVASCRIPT… | MEDIUM | 5.3 | Oct 17, 2024 |
| CVE-2024-3184 | Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when compiled with the ME_GOAHEAD_REPLACE_MALLOC… | MEDIUM | 5.9 | Oct 17, 2024 |
| CVE-2021-41615 | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which d… | CRITICAL | 9.8 | Aug 8, 2022 |
| CVE-2021-43298 | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that a… | CRITICAL | 9.8 | Jan 25, 2022 |
| CVE-2021-42342 | An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed… | CRITICAL | 9.8 | Oct 14, 2021 |
| CVE-2020-15688 | The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote… | HIGH | 8.8 | Jul 23, 2020 |
| CVE-2019-5096 | An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in version… | CRITICAL | 9.8 | Dec 3, 2019 |
| CVE-2019-5097 | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.… | HIGH | 7.5 | Dec 3, 2019 |
| CVE-2019-19240 | Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limi… | MEDIUM | 5.3 | Nov 22, 2019 |
| CVE-2019-16645 | An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtaine… | HIGH | 8.6 | Sep 20, 2019 |
| CVE-2019-12822 | In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and… | HIGH | 7.5 | Jun 14, 2019 |
| CVE-2018-15505 | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause… | HIGH | 7.5 | Aug 18, 2018 |
| CVE-2018-15504 | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which r… | HIGH | 7.5 | Aug 18, 2018 |
| CVE-2017-1000471 | EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service. | CRITICAL | 9.8 | Jan 3, 2018 |
| CVE-2017-17562 KEV | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the env… | HIGH | 8.1 | Dec 12, 2017 |
| CVE-2017-14149 | GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request. | HIGH | 7.5 | Sep 5, 2017 |
| CVE-2017-5675 | A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera… | HIGH | 8.8 | Mar 13, 2017 |
| CVE-2017-5674 | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malforme… | CRITICAL | 9.8 | Mar 13, 2017 |
| CVE-2014-9707 | EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traver… | HIGH | 7.5 | Mar 31, 2015 |
Showing 1 to 17 of 17 CVEs