VendorsCraftycontrolcrafty_controllerall versions
Vulnerabilities

Craftycontrol Arcadia Technology Crafty Controller

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-14700
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
Published 2025-12-17 · Analyzed
9.9EPSS 0.066
CVE-2026-0963
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller
Published 2026-01-30 · Analyzed
9.9EPSS 0.007
CVE-2026-13716
Path Traversal: '.../...//' in Crafty Controller
Published 2026-08-11 · Analyzed
9.1EPSS 0.008
CVE-2026-5652
Authorization Bypass Through User-Controlled Key in Crafty Controller
Published 2026-04-21 · Analyzed
9.0EPSS 0.005
CVE-2026-0805
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller
Published 2026-01-30 · Analyzed
8.8EPSS 0.006
CVE-2025-5990
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controller
Published 2025-06-15 · Analyzed
7.6EPSS 0.003
CVE-2024-1064
Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4
Published 2024-02-03 · Modified
7.5EPSS 0.008
CVE-2025-14701
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controller
Published 2025-12-17 · Analyzed
7.1EPSS 0.003