Vulnerabilities > Metersphere > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-41878 Use of Hard-coded Credentials vulnerability in Metersphere
MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and performance testing.
network
low complexity
metersphere CWE-798
critical
9.8
2023-07-17 CVE-2023-37461 Path Traversal vulnerability in Metersphere
Metersphere is an opensource testing framework.
network
low complexity
metersphere CWE-22
critical
9.8
2023-05-08 CVE-2023-29944 Unspecified vulnerability in Metersphere 1.20.20Lts79D354A6
Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution.
network
low complexity
metersphere
critical
9.8
2022-09-29 CVE-2021-45790 Unrestricted Upload of File with Dangerous Type vulnerability in Metersphere 1.15.4
An arbitrary file upload vulnerability was found in Metersphere v1.15.4.
network
low complexity
metersphere CWE-434
critical
9.8