VendorsYogesh Ojharengineany version
Vulnerabilities

Yogesh Ojha reNgine any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-38606
reNgine through 0.5 relies on a predictable directory name.
Published 2021-08-12 · Modified
9.8EPSS 0.012
CVE-2023-50094
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.
Published 2024-01-01 · Modified
8.8EPSS 0.135
CVE-2025-24968
Business Logic And Unrestricted Project Deletion Lead To Take Over the System in reNgine
Published 2025-02-04 · Analyzed
8.8EPSS 0.006
CVE-2025-24899
Disclosure of Sensitive User Information via API in reNgine
Published 2025-02-03 · Analyzed
7.5EPSS 0.005
CVE-2025-24967
Stored XSS on Admin Panel When Deleting a User in reNgine
Published 2025-02-04 · Analyzed
7.4EPSS 0.003
CVE-2025-61319
ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account.
Published 2025-10-10 · Analyzed
6.1EPSS 0.003
CVE-2024-43381
reNgine vulnerable to Stored Cross-Site Scripting (XSS) via DNS Record Poisoning
Published 2024-08-16 · Analyzed
5.4EPSS 0.004
CVE-2025-24966
HTML Injection in reNgine
Published 2025-02-04 · Analyzed
5.4EPSS 0.003