Known Vulnerabilities for products from Web2py

Listed below are 13 of the newest known vulnerabilities associated with the vendor "Web2py".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-45158 json An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHa... 9.8 - CRITICAL 2023-10-16 2023-10-18
CVE-2023-22432 json Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected t... 6.1 - MEDIUM 2023-03-06 2023-03-13
CVE-2022-33146 json Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary we... 6.1 - MEDIUM 2022-06-27 2022-07-07
CVE-2016-10321 json web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to pe... Not Provided 2017-04-10 2025-04-20
CVE-2016-4808 json Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to... Not Provided 2017-01-11 2026-05-06
CVE-2016-4807 json Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS atta... Not Provided 2017-01-11 2026-05-06
CVE-2016-4806 json Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user t... Not Provided 2017-01-11 2026-05-06
CVE-2016-3957 json The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information store... 9.8 - CRITICAL 2018-02-06 2019-06-21
CVE-2016-3954 json web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_e... 5.5 - MEDIUM 2018-02-06 2019-06-21
CVE-2016-3953 json The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involvi... 9.8 - CRITICAL 2018-02-06 2019-06-21
CVE-2016-3952 json web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a ... 7.8 - HIGH 2018-02-06 2019-06-21
CVE-2015-6961 json Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sit... Not Provided 2017-10-18 2025-04-20
CVE-2013-2311 json Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 all... Not Provided 2013-05-22 2026-04-29

Known software with vulnerabilities from Web2py

Type Vendor Product Version
ApplicationWeb2pyWeb2py1.76.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report