Appspace develops a narrowly scoped digital signage and content-management platform with both cloud and on-premises deployment options that serves as a high-visibility display and communication layer in enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, concentrating in web-application and authentication weaknesses such as cross-site scripting, CSRF, improper authentication, and server-side request forgery that are endemic to internet-facing management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Appspace over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27670CRITICAL Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. | Feb 25, 2021 | 9.8 | 73 | NO | YES |
CVE-2021-27990HIGH Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus an | Apr 14, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-27704MEDIUM Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page. | Nov 12, 2024 | 6.5 | 20 | NO | NO |
CVE-2021-27564MEDIUM A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups section of the network tab, it is stored as the group name. Wh | Feb 22, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-27989MEDIUM Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx. | Apr 14, 2021 | 5.4 | 18 | NO | NO |
CVE-2020-5393MEDIUM In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS. | Jan 7, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Appspace.
Media articles that mention a CVE ID that affects a product developed by Appspace — matched by CVE ID, not by vendor name.