freewvs
A local web vulnerability scanner.
freewvs is a tool to search webroots for known vulnerable versions of web applications.
install
You can install freewvs via pip:
pip install freewvs
Alternatively, you can run freewvs directly from the git source.
If you install via pip, you need to update the freewvs database first:
update-freewvsdb
usage
Just run freewvs with a path, e.g.:
freewvs /var/www
The output will be something like this:
Joomla 3.9.11 (3.9.14) CVE-2019-19846 /var/www/example.org
nextcloud 14.0.1 (14.0.5) CVE-2019-5449 /var/www/cloud.example.org
MediaWiki 1.31.1 (1.31.6) CVE-2019-19709 /var/www/wiki.example.org
faq
What does freewvs do?
It scans your webroot for known vulnerable versions of popular web applications.
What does the output tell me?
The output looks like this:
Joomla-3 3.9.11 (3.9.13) CVE-2019-18674 /home/joe/websites/joessite/
This says that in /home/joe/websites/joessite/, there's a Joomla installation of version 3.9.11. This version is vulnerable to CVE-2019-18674, and you should update it to version 3.9.13.
CVE-2019-XXXX seems to be very minor, at least it doesn't affect me. Am I safe?
No, as freewvs only checks for the latest vulnerabilities. There may be other vulnerabilities in your version not listed by freewvs. The only way to be sure is to check the upstream changelog.
There is no version inside the brackets. What does that mean?
It means your web application has not released a security update. Often, this means the software is no longer developed.
contributions
See CONTRIBUTIONS.md.
misc
freewvs was developed by schokokeks.org hosting.
It's licensed under the 0BSD license.
Metadata
Release files for freewvs 0.1.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| freewvs-0.1.5.tar.gz | 19.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| freewvs-0.1.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.6 kB
Release files / freewvs-0.1.5.tar.gz
| Download URL | freewvs-0.1.5.tar.gz |
|---|---|
| Size | 19.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1faf36f982e51b5d83e8a8e80d12cd8425685db81f86173312192bf41a80c779
|
|
BLAKE2b-256 checksum How to use checksums |
f588192ecd23a1de3e61739d327a20f05f8a7f1270a77501020c7db8c893d0b9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.2
|
Release files / freewvs-0.1.5-py3-none-any.whl
| Download URL | freewvs-0.1.5-py3-none-any.whl |
|---|---|
| Size | 5.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ac7c8058e51a59904b129580f894fa37e230d4c9583d859b63fc566443701225
|
|
BLAKE2b-256 checksum How to use checksums |
414d7d4557a0d36858c92c76d343135f2ed35d0f0bea2a2a70df541c9ccdbe9a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.2
|