CVE-2016-4808Medium· 4.5▾ TwilightPoC availableWeb2py Cross-Site Request Forgery vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 24.8 · likelihood 0.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.7%
1.7% → 1.8%
Exploit-DB (last check)
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged-in administrator into performing unwanted actions i.e An attacker can trick a victim into disable the installed application just by visiting a URL.
web2py < 2.14.6Upgrade to a patched release:
web2py 2.14.6Connected by shared product, vendor, weakness, or advisory.
CVE-2016-4807Medium· 4.8Web2py Reflected XSS vulnerability
CVE-2026-25198Medium· 4.7web2py has an Open Redirect Vulnerability
CVE-2016-3954Medium· 5.5web2py exposure of sensitive information
CVE-2022-33146Medium· 6.1Open redirect in web2py
CVE-2023-22432Medium· 6.1Open redirect in web2py