lansweeper CVE Vulnerabilities & Metrics

Focus on lansweeper vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About lansweeper Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with lansweeper. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total lansweeper CVEs: 18
Earliest CVE date: 29 May 2017, 17:29 UTC
Latest CVE date: 15 Dec 2022, 10:15 UTC

Latest CVE reference: CVE-2022-32763

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical lansweeper CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.88

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 9
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS lansweeper CVEs

These are the five CVEs with the highest CVSS scores for lansweeper, sorted by severity first and recency.

All CVEs for lansweeper

CVE-2022-32763 lansweeper vulnerability CVSS: 0 15 Dec 2022, 10:15 UTC

A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-32573 lansweeper vulnerability CVSS: 0 15 Dec 2022, 10:15 UTC

A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-29517 lansweeper vulnerability CVSS: 0 15 Dec 2022, 10:15 UTC

A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-29511 lansweeper vulnerability CVSS: 0 15 Dec 2022, 10:15 UTC

A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-28703 lansweeper vulnerability CVSS: 0 15 Dec 2022, 10:15 UTC

A stored cross-site scripting vulnerability exists in the HdConfigActions.aspx altertextlanguages functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-27498 lansweeper vulnerability CVSS: 0 15 Dec 2022, 10:15 UTC

A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-22149 lansweeper vulnerability CVSS: 6.5 14 Apr 2022, 20:15 UTC

A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-21234 lansweeper vulnerability CVSS: 6.5 14 Apr 2022, 20:15 UTC

An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-21210 lansweeper vulnerability CVSS: 6.5 14 Apr 2022, 20:15 UTC

An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-21145 lansweeper vulnerability CVSS: 3.5 14 Apr 2022, 20:15 UTC

A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-13658 lansweeper vulnerability CVSS: 6.0 30 Sep 2020, 18:15 UTC

In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.

CVE-2020-14011 lansweeper vulnerability CVSS: 7.5 15 Jun 2020, 15:15 UTC

Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled Deployments features.

CVE-2019-18955 lansweeper vulnerability CVSS: 4.3 19 Dec 2019, 17:15 UTC

The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019.

CVE-2019-13462 lansweeper vulnerability CVSS: 6.4 12 Aug 2019, 17:15 UTC

Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.

CVE-2015-9264 lansweeper vulnerability CVSS: 7.5 27 Aug 2018, 04:29 UTC

Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation via a crafted Windows service.

CVE-2017-16841 lansweeper vulnerability CVSS: 4.3 16 Nov 2017, 03:29 UTC

LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.

CVE-2017-13706 lansweeper vulnerability CVSS: 6.5 10 Oct 2017, 13:29 UTC

XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705.

CVE-2017-9292 lansweeper vulnerability CVSS: 4.3 29 May 2017, 17:29 UTC

Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782.