Adive develops a web application framework with a vulnerability profile centered on input-handling and session-management issues, specifically cross-site scripting and cross-site request forgery. These weakness classes reflect the common exposure surface of framework-based applications and their reliance on proper sanitization and token validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adive over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7991HIGH Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. | Jan 26, 2020 | 8.8 | 39 | NO | YES |
CVE-2024-4337HIGH Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in mult | Apr 30, 2024 | 7.4 | 22 | NO | NO |
CVE-2024-4336HIGH Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in m | Apr 30, 2024 | 7.4 | 22 | NO | NO |
CVE-2020-7990MEDIUM Adive Framework 2.0.8 has admin/user/add userName XSS. | Jan 26, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-7989MEDIUM Adive Framework 2.0.8 has admin/user/add userUsername XSS. | Jan 26, 2020 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adive.
Media articles that mention a CVE ID that affects a product developed by Adive — matched by CVE ID, not by vendor name.