RaspAP has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.4 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.4
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
RaspAP vulnerabilities
CVEs affecting RaspAP, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-101860High· 8.8A vulnerability was found in RaspAP raspap-webgui up to 3.5.5
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipu…
CVE-2026-101859Medium· 5.4A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5
A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation …
CVE-2026-101858Medium· 4.7A flaw has been found in RaspAP raspap-webgui up to 3.5.5
A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argu…