VendorsRapid7appspider_proall versions
Vulnerabilities

Rapid7 Appspider Pro

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2017-5236
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Published 2017-05-03 · Modified
7.8EPSS 0.009
CVE-2017-5233
Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Published 2017-03-02 · Modified
7.8EPSS 0.009
CVE-2017-5240
Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the application to crash.
Published 2017-05-03 · Modified
7.5EPSS 0.010
CVE-2025-4951
Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of version 7.5.018
Published 2025-05-20 · Analyzed
4.6EPSS 0.002
CVE-2025-36857
Rapid7 Appspider Broken Access Control Vulnerability
Published 2025-09-25 · Analyzed
3.3EPSS 0.001
CVE-2025-11195
Rapid7 AppSpider Project Name Validation Bypass
Published 2025-09-30 · Analyzed
3.3EPSS 0.001