Adata's vulnerability footprint is confined to its employee-facing portal product, where the durable signal centers on access-control and input-handling defects such as authorization bypass through user-controlled keys and cross-site scripting. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adata over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-61075HIGH Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry out administrative fun | Dec 9, 2025 | 8.1 | 25 | NO | NO |
CVE-2025-61074MEDIUM A stored Cross Site Scripting (XSS) vulnerability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeiter Portal 2.15.2.0 allows remote authenticated users to exec | Dec 9, 2025 | 4.6 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adata.
Media articles that mention a CVE ID that affects a product developed by Adata — matched by CVE ID, not by vendor name.