Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-56260 Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path param… Crawl4ai 0.8.7+ Fix from $2,3002026-07-12 HIGH 8.2 CVE-2026-56259 Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to att… Crawl4ai 0.8.8+ Fix from $1,9502026-07-12 HIGH 7.5 CVE-2026-56261 Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which… Crawl4ai 0.8.7+ Fix from $1,9502026-07-10 CRITICAL 10.0 CVE-2026-57572 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra… Crawl4ai 0.9.0+ Fix from $2,3002026-07-06 HIGH 8.6 CVE-2026-57573 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-… Crawl4ai 0.9.0+ Fix from $1,9502026-07-06 CRITICAL 9.6 CVE-2026-57571 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w… Crawl4ai 0.9.0+ Fix from $2,3002026-07-06 MEDIUM 6.1 CVE-2026-56264 Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and exe… Crawl4ai 0.8.7+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-56262 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access… Crawl4ai 0.8.7+ Fix from $1,6002026-06-24 CRITICAL 10.0 CVE-2026-53753 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature us… Crawl4ai 0.8.7+ Fix from $2,3002026-06-23 HIGH 7.5 CVE-2026-53754 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / valida… Crawl4ai 0.8.8+ Fix from $1,9502026-06-23 HIGH 7.5 CVE-2026-53755 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl … Crawl4ai 0.8.9+ Fix from $1,9502026-06-23 HIGH 8.1 CVE-2026-56258 Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to wri… Crawl4ai 0.8.8+ Fix from $1,9502026-06-23 MEDIUM 6.1 CVE-2026-56263 Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via in… Crawl4ai 0.8.7+ Fix from $1,6002026-06-23 HIGH 8.6 CVE-2026-56266 Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary… Crawl4ai 0.8.7+ Fix from $1,9502026-06-22 CRITICAL 9.8 CVE-2026-56265 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers … Crawl4ai 0.8.7+ Fix from $2,3002026-06-21 CRITICAL 10.0 CVE-2026-26216 Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks para… Crawl4ai 0.8.0+ Fix from $2,3002026-02-12 HIGH 7.5 CVE-2026-26217 Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /… Crawl4ai 0.8.0+ Fix from $1,9502026-02-12 CRITICAL 9.1 CVE-2025-28197 Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py. Crawl4ai after 0.4.247 Fix from $2,3002025-04-18