Skip to content

Known CVE

Web-Check < 2.0.1 Screenshot API - OS Command Injection

Lissy93/web-check contains a command injection caused by unsanitized user input in the screenshot API, letting attackers execute arbitrary system commands, exploit requires sending crafted url parameters.

CVE-2025-32778

Critical2025CVSS 9.8CWE-78

cve2025 · web-check · rce · injection · unauth · oast · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website