substack has 2 CVEs on record between 2020 and 2022. The median CVSS is 7.7 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- minimist 2
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2021-44906Critical· 9.8Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).67CVE-2020-7598Medium· 5.6minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.43
substack vulnerabilities
CVEs affecting substack, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2021-44906Critical· 9.8PoCMinimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
▾ Abyssalsubstack · minimistEPSS 4.6%via NVD
CVE-2020-7598Medium· 5.6PoCminimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
▾ Twilightsubstack · minimistEPSS 1.9%via NVD