Alltena's vulnerability footprint centers on Allegra, a modestly represented product within a narrow portfolio that occupies a position of prominence in its specialized domain. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the nature of the flaws that recur in the product's design. The exposure concentrates around weaknesses in access control, template handling, deserialization logic, and path traversal protections, characteristic issues that arise when user input or configuration data flows through security-sensitive code paths without proper validation or containment. Defenders should prioritize Allegra instances for patching and configuration hardening, particularly where the product handles untrusted input or processes external data. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alltena over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6216CRITICAL Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations o | Jun 21, 2025 | 9.8 | 54 | NO | YES |
CVE-2023-51639CRITICAL Allegra downloadExportedChart Directory Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations | Nov 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-51638CRITICAL Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authen | Nov 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-3485HIGH Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o | Jun 6, 2025 | 8.8 | 26 | NO | NO |
CVE-2025-3486HIGH Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of | May 22, 2025 | 8.8 | 24 | NO | NO |
CVE-2023-51644HIGH Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Nov 22, 2024 | 7.3 | 24 | NO | NO |
CVE-2024-5581HIGH Allegra unzipFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra | Nov 22, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-5580HIGH Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected insta | Nov 22, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-5579HIGH Allegra renderFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins | Nov 22, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-30372MEDIUM Allegra getLinkText Server-Side Template Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio | Nov 22, 2024 | 6.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alltena.
Media articles that mention a CVE ID that affects a product developed by Alltena — matched by CVE ID, not by vendor name.