Vulnerabilities
10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13716 | Authenticated Path Traversal to RCE in Crafty Controller Crafty Controller, an open-source web panel for managing game servers, contains a path-traversal flaw (CWE-35) in its server import and administrator file-upload features. An attacker holding valid, low-privilege authentication credentials can upload crafted files to arbitrary filesystem paths that the application is permitted to write. By placing attacker-controlled files in privileged locations, the attacker achieves remote code execution on the host running the panel, consistent with the changed-scope (S:C) component of the 9.1 CVSS score. The flaw affects Crafty Controller deployments; the published references point to the Crafty 4 (crafty-4) codebase, but no specific vulnerable version ranges were provided in the available data. There is currently no evidence of exploitation in the wild (not listed in CISA KEV, EPSS 0.7%), and two public PoC/tracker references exist, so defenders should treat this as a critical but not yet actively exploited issue. Do: Upgrade Crafty Controller to the latest release as soon as the vendor's fix is published, and monitor the vendor's GitLab work items (727 and 740) for the patched version and affected version ranges. Until patched, restrict who has valid panel credentials, limit the panel's internet exposure (VPN or allowlist), and consider disabling or tightly controlling the server import and admin file-upload features. Review application and web logs for unexpected file uploads or writes to unusual paths. | 9.1 | <1% | PoC ×2 |
| nichelikely low thousands to low tens of thousands of self-hosted panels (order-of-magnitude estimate) | |
| CVE-2026-5652 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modifi An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation. NVD description · AI analysis pending | 9.0 | <1% | PoC |
| — | |
| CVE-2026-0963 +1 in the same advisory: …0805 | An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-14700 +1 in the same advisory: …14701 | An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code exec An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection. NVD description · AI analysis pending | 9.9 group max | 7% |
| — | ||
| CVE-2025-5990 | An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perfor An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-1064 | A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Servic A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2020-9048 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker o A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack. NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2020-9045 | During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used t During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation. NVD description · AI analysis pending | 6.5 | <1% |
| — |