WebsvnCVEs & Vulnerabilities

7 CVEs affecting Websvn products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

websvn 12
CVE-2021-32305KEVCRITICALin the wild

WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

11 Apr 2026
9.8
CVSS
CVE-2011-2195CRITICAL

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

26 Oct 2021
9.8
CVSS
CVE-2016-1236MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.

12 May 2016
6.1
CVSS
CVE-2016-2511MEDIUM

Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.

8 Apr 2016
6.1
CVSS
CVE-2013-6892LOW

WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.

21 Jan 2015
3.5
CVSS
CVE-2011-5221MEDIUM

Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to (1) comp.php, (2) diff.php, or (3) revision.php.

25 Oct 2012
4.3
CVSS
CVE-2007-3056MEDIUM

Cross-site scripting (XSS) vulnerability in filedetails.php in WebSVN 2.0rc4, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the path parameter.

6 Jun 2007
4.3
CVSS
← PrevPage 1 / 1Next →