Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    4
    Critical Level Threats
    3
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-25198

    Open Redirect Vulnerability Enabling Phishing in web2py

    Last Modified: Apr 17, 2026
    Published: Feb 05, 2026

    CVE-2023-45158

    An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.

    Last Modified: Nov 21, 2024
    Published: Oct 16, 2023

    CVE-2023-22432

    Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

    Last Modified: Mar 07, 2025
    Published: Mar 05, 2023

    CVE-2022-33146

    Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

    Last Modified: Nov 21, 2024
    Published: Jun 27, 2022

    CVE-2016-3954

    web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: this issue can be leveraged by remote attackers to execute arbitrary code using CVE-2016-3957.

    Last Modified: Nov 21, 2024
    Published: Feb 06, 2018
    Items Per Page
    Web2py Vulnerabilities & Security CVEs | CVE-DB