Webpagetest Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 11
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    10
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2012-10049

    WebPageTest Arbitrary PHP File Upload RCE

    Last Modified: Apr 15, 2026
    Published: Aug 08, 2025

    CVE-2017-6536

    Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (url, pssid) passed to the webpagetest-master/www/weblite.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Last Modified: Apr 20, 2025
    Published: Mar 08, 2017

    CVE-2017-6539

    Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/delta.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Last Modified: Apr 20, 2025
    Published: Mar 08, 2017

    CVE-2017-6540

    Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (configs) passed to the webpagetest-master/www/benchmarks/compare.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Last Modified: Apr 20, 2025
    Published: Mar 08, 2017

    CVE-2017-6534

    A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (pssid) passed to the webpagetest-master/www/pss.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Last Modified: Apr 20, 2025
    Published: Mar 08, 2017
    Items Per Page
    Webpagetest_Project Vulnerabilities & Security CVEs | CVE-DB