Abbyy develops document-capture and intelligent-document-processing software, with a focused portfolio centered on products such as FlexiCapture and FineReader that perform optical character recognition and form automation in enterprise workflows. The durable exposure signal reflects application-layer weaknesses including CSRF, SQL injection, improper file-access handling, and permission-assignment flaws that recur in web-facing and data-processing components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Abbyy over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-13792CRITICAL Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via t | Feb 10, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-20383HIGH ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using | Aug 13, 2020 | 7.8 | 26 | NO | NO |
CVE-2018-13791CRITICAL The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCaptu | Jul 9, 2018 | 9.8 | 26 | NO | NO |
CVE-2018-13793HIGH Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Verification, Web Scanning, Web Capture, | Jul 9, 2018 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Abbyy.
Media articles that mention a CVE ID that affects a product developed by Abbyy — matched by CVE ID, not by vendor name.