webpy
Products
1- 5 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-79313 | Cri | 0.64 | 9.8 | 0.00 | Sep 22, 2026 | webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been… | ||
| CVE-2026-79310 | Hig | 0.55 | 8.5 | 0.01 | Sep 23, 2026 | webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application precompiles templates from a directory the… | ||
| CVE-2026-79312 | Med | 0.44 | 6.8 | 0.00 | Sep 22, 2026 | webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation after authentication, so a fixed session_id… | ||
| CVE-2025-3818 | Med | 0.41 | 6.3 | 0.00 | Apr 19, 2025 | A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The… | ||
| CVE-2026-79311 | Med | 0.40 | 6.1 | 0.00 | Sep 22, 2026 | webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__(). |
- risk 0.64cvss 9.8epss 0.00
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been…
- risk 0.55cvss 8.5epss 0.01
webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application precompiles templates from a directory the…
- risk 0.44cvss 6.8epss 0.00
webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation after authentication, so a fixed session_id…
- risk 0.41cvss 6.3epss 0.00
A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The…
- risk 0.40cvss 6.1epss 0.00
webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().