Rapid7 Vulnerabilities and Affected Products
Vulnerabilities associated with AppSpider Pro.
Products
Clear product- Velociraptor32 vulnerabilities
- Nexpose17 vulnerabilities
- Insight Agent10 vulnerabilities
- InsightVM9 vulnerabilities
- AppSpider Pro6 vulnerabilities
- Metasploit Framework6 vulnerabilities
- Metasploit Pro6 vulnerabilities
- Metasploit4 vulnerabilities
- InsightCloudSec3 vulnerabilities
- InsightConnect Sed Plugin3 vulnerabilities
- AppSpider2 vulnerabilities
- Insight Platform2 vulnerabilities
- Insight Collector1 vulnerability
- InsightAppSec1 vulnerability
- InsightConnect AWK Plugin1 vulnerability
- InsightConnect Compression Plugin1 vulnerability
- InsightConnect Finger Plugin1 vulnerability
- InsightConnect Markdown Plugin1 vulnerability
- InsightConnect Ping Plugin1 vulnerability
- InsightConnect RPM Plugin1 vulnerability
- InsightConnect SQLmap Plugin1 vulnerability
- InsightConnect Tcpdump Plugin1 vulnerability
- InsightConnect TR Plugin1 vulnerability
- InsightConnect Traceroute Plugin1 vulnerability
- InsightVM Virtual Appliance1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Rapid7 AppSpider Project Name Validation BypassRapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack of effective verification of the uniqueness of project names when editing them outside the application in affected versions. This vulnerability was remediated in version 7.5.021 of the product. | CVSS3.3v3.1 | EPSS0.084% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Rapid7 Appspider Broken Access Control VulnerabilityRapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place files in directories belonging to other users or projects. Affected versions allow standard users to add custom configuration files. These files, which are loaded in alphabetical order, can override or change the settings of the original configuration files, creating a security vulnerability. This issue stems from … CWE-276Sep 25, 2025 | CVSS3.3v3.1 | EPSS0.118% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-4951MEDIUM | Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of version 7.5.018 CWE-79May 20, 2025 | CVSS4.6v3.1 | EPSS0.172% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-5240HIGH | Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the application to crash. CWE-119May 3, 2017 | CVSS7.5v3.0 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-5236HIGH | Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer. CWE-426May 3, 2017 | CVSS7.8v3.0 | EPSS0.93% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-5233HIGH | Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer. CWE-426Mar 2, 2017 | CVSS7.8v3.1 | EPSS0.875% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |