Antsword Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-43892

    AntSword: Incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection

    Last Modified: May 13, 2026
    Published: May 12, 2026

    CVE-2020-18766

    A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.

    Last Modified: Nov 21, 2024
    Published: Oct 26, 2020

    CVE-2020-25470

    AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.

    Last Modified: Nov 21, 2024
    Published: Oct 26, 2020

    CVE-2019-13970

    In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js.

    Last Modified: Nov 21, 2024
    Published: Jul 19, 2019
    Items Per Page