Filtered by vendor Arcadia Technology Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-14700 1 Arcadia Technology 1 Crafty Controller 2025-12-17 9.9 Critical
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.
CVE-2025-14701 1 Arcadia Technology 1 Crafty Controller 2025-12-17 7.1 High
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.