Hallo Welt! GmbH
First CVE: Jul 22, 2022Active for: 4 years
16
CVEs Published
More CVEs Published than 36% of tracked CNAs
4.0
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
5.6
Avg CVSS Score
Higher Avg CVSS Score than 6% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Hallo Welt! GmbH over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2022
4 years ago
Most Recent CVE
Mar 4, 2026
144 days ago
Top CVEs
All CVEs published by Hallo Welt! GmbH as a CNA, regardless of affected vendor or product.
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24732MEDIUM Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules | Mar 4, 2026 | 6.6 | 23 | NO | NO |
CVE-2025-48007MEDIUM Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS).
This issue affects BlueSpice: fr | Sep 19, 2025 | 6.4 | 22 | NO | NO |
CVE-2025-46703MEDIUM Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-Site Scripting (XSS).
This issue affects BlueSpice: from 5 t | Sep 19, 2025 | 6.4 | 22 | NO | NO |
CVE-2022-3895MEDIUM Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS). | Nov 15, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-2511MEDIUM Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of th | Jul 22, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-2510MEDIUM Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", | Jul 22, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-41814MEDIUM Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the histo | Nov 15, 2022 | 5.4 | 21 | NO | NO |
CVE-2025-57880MEDIUM Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) allows Cross-Site Scripting (XSS).
This issue affects BlueSpice | Sep 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2022-42001MEDIUM Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the book n | Nov 15, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-42000MEDIUM Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permissions to inject arbitrary HTML into the comment section of | Nov 15, 2022 | 5.4 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA16 CVEs
100%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (18.8%)
Unknown0 (0.0%)
Required13 (81.3%)
Privileges Required
Low9 (56.3%)
High3 (18.8%)
None4 (25.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Hallo Welt! GmbH as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Hallo Welt! GmbH as a CNA — matched by CVE ID, not by organization name.