Havenweb

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 2
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-39906

    Remote code execution in Haven IndieAuthClient (GHSL-2024-093)

    Last Modified: Apr 15, 2026
    Published: Jul 19, 2024

    CVE-2023-24060

    Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RSS Feeds or add RSS Feeds can supply an arbitrary hostname (or even the hostname of the Haven server itself). NOTE: this product has significant usage but does not have numbered releases; ordinary end users may typically use the master branch.

    Last Modified: Mar 27, 2025
    Published: Jan 27, 2023
    Items Per Page
    Havenweb Vulnerabilities & Security CVEs | CVE-DB