thecontrolgroup CVE Vulnerabilities & Metrics

Focus on thecontrolgroup vulnerabilities and metrics.

Last updated: 07 Jun 2025, 22:25 UTC

About thecontrolgroup Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with thecontrolgroup. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total thecontrolgroup CVEs: 5
Earliest CVE date: 30 Sep 2019, 19:15 UTC
Latest CVE date: 30 Jan 2025, 15:15 UTC

Latest CVE reference: CVE-2024-55417

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical thecontrolgroup CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.3

Max CVSS: 6.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 1
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS thecontrolgroup CVEs

These are the five CVEs with the highest CVSS scores for thecontrolgroup, sorted by severity first and recency.

All CVEs for thecontrolgroup

CVE-2024-55417 thecontrolgroup vulnerability CVSS: 0 30 Jan 2025, 15:15 UTC

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.

CVE-2024-55416 thecontrolgroup vulnerability CVSS: 0 30 Jan 2025, 15:15 UTC

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.

CVE-2024-55415 thecontrolgroup vulnerability CVSS: 0 30 Jan 2025, 15:15 UTC

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

CVE-2020-36070 thecontrolgroup vulnerability CVSS: 0 26 Apr 2023, 20:15 UTC

Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.

CVE-2019-17050 thecontrolgroup vulnerability CVSS: 6.5 30 Sep 2019, 19:15 UTC

An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment.