Activecollab is a web-based project management and collaboration platform whose vulnerability profile centers on input-handling issues at the application layer, specifically cross-site scripting and improper input validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Activecollab over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0215MEDIUM ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL. | Jan 7, 2011 | 6.0 | 21 | NO | NO |
CVE-2009-1773MEDIUM activeCollab 2.1 Corporate allows remote attackers to obtain sensitive information via an invalid re_route parameter to the login script, which reveals the installation path in an | May 22, 2009 | 5.0 | 16 | NO | NO |
CVE-2009-2041MEDIUM Cross-site scripting (XSS) vulnerability in A51 D.O.O. activeCollab 0.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulner | Jun 12, 2009 | 4.3 | 15 | NO | NO |
CVE-2009-1772MEDIUM Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web script or HTML via the re_route parameter to the login script | May 22, 2009 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Activecollab.
Media articles that mention a CVE ID that affects a product developed by Activecollab — matched by CVE ID, not by vendor name.