Known Vulnerabilities for Crater by Craterapp
Listed below are 9 of the newest known vulnerabilities associated with "Crater" by "Craterapp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-14791 json | A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the ... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2023-46865 json | /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP cod... | 7.2 - HIGH | 2023-10-30 | 2023-11-08 |
| CVE-2022-1033 json | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | 7.8 - HIGH | 2022-03-23 | 2022-03-28 |
| CVE-2022-1032 json | Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | 7.2 - HIGH | 2022-03-29 | 2022-04-04 |
| CVE-2022-0515 json | Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. | 4.3 - MEDIUM | 2022-03-21 | 2022-03-28 |
| CVE-2022-0514 json | Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. | 6.5 - MEDIUM | 2022-03-21 | 2022-03-28 |
| CVE-2022-0372 json | Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. | 5.4 - MEDIUM | 2022-01-27 | 2022-02-02 |
| CVE-2022-0242 json | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. | 7.2 - HIGH | 2022-01-17 | 2022-01-25 |
| CVE-2022-0203 json | Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. | 5.3 - MEDIUM | 2022-01-26 | 2022-02-02 |
| CVE-2021-4080 json | crater is vulnerable to Unrestricted Upload of File with Dangerous Type | 8.8 - HIGH | 2022-01-12 | 2022-01-18 |