digitaldruid has 2 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 7.0 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2025-44203High· 7.5In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking53CVE-2023-34854Medium· 6.6HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.36
digitaldruid vulnerabilities
CVEs affecting digitaldruid, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2023-34854Medium· 6.6HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
▾ Sunlitdigitaldruid · HotelDruidEPSS 0.23%via NVD
CVE-2025-44203High· 7.5PoCIn HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a…
▾ Midnightdigitaldruid · hoteldruidEPSS 0.57%via NVD