VendorsYogesh Ojharengineall versions
Vulnerabilities

Yogesh Ojha reNgine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2022-28995
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
Published 2022-05-20 · Modified
9.8EPSS 0.023
CVE-2022-36566
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
Published 2022-08-31 · Modified
9.8EPSS 0.021
CVE-2021-38606
reNgine through 0.5 relies on a predictable directory name.
Published 2021-08-12 · Modified
9.8EPSS 0.012
CVE-2023-50094
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.
Published 2024-01-01 · Modified
8.8EPSS 0.135
CVE-2024-58287
reNgine 2.2.0 Authenticated Command Injection via Scan Engine Configuration
Published 2025-12-11 · Analyzed
8.8EPSS 0.034
CVE-2025-24962
Command Injection in reNgine
Published 2025-02-03 · Analyzed
8.8EPSS 0.007
CVE-2025-24968
Business Logic And Unrestricted Project Deletion Lead To Take Over the System in reNgine
Published 2025-02-04 · Analyzed
8.8EPSS 0.006
CVE-2025-24899
Disclosure of Sensitive User Information via API in reNgine
Published 2025-02-03 · Analyzed
7.5EPSS 0.005
CVE-2025-24967
Stored XSS on Admin Panel When Deleting a User in reNgine
Published 2025-02-04 · Analyzed
7.4EPSS 0.003
CVE-2025-61319
ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account.
Published 2025-10-10 · Analyzed
6.1EPSS 0.003
CVE-2024-43381
reNgine vulnerable to Stored Cross-Site Scripting (XSS) via DNS Record Poisoning
Published 2024-08-16 · Analyzed
5.4EPSS 0.004
CVE-2025-24966
HTML Injection in reNgine
Published 2025-02-04 · Analyzed
5.4EPSS 0.003