Annexcloud maintains a loyalty experience platform where the observed vulnerability surface centers on access-control and authorization mechanisms, including user-controlled authorization keys, permission assignment flaws, and related authorization-bypass patterns. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Annexcloud over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31928HIGH Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadministrator. It was fixed in v2021.1.0.2. | Jun 10, 2021 | 8.8 | 25 | NO | NO |
CVE-2021-31927MEDIUM An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, inclu | Jun 10, 2021 | 4.3 | 16 | NO | NO |
CVE-2021-31929MEDIUM Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templ | Jun 10, 2021 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Annexcloud.
Media articles that mention a CVE ID that affects a product developed by Annexcloud — matched by CVE ID, not by vendor name.