Archer
Vendor:
First CVE: May 1, 2023 · Active for 3 years
28
Total CVEs
More Total CVEs than 96% of tracked products
9.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Archer over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2023
3 years ago
Most Recent CVE
Mar 11, 2025
503 days ago
CVE Severity & Scoring
Archer28 CVEs
82%
14%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (3.6%)
Network27 (96.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None12 (42.9%)
Unknown0 (0.0%)
Required16 (57.1%)
Privileges Required
Low23 (82.1%)
High0 (0.0%)
None5 (17.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32761HIGH Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via | Jul 14, 2023 | 8.0 | 25 | NO | NO |
CVE-2024-34092HIGH An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is also a fixed re | May 6, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-48641HIGH Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation cou | Dec 12, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-45357MEDIUM Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitiv | Oct 17, 2023 | 6.5 | 20 | NO | NO |
CVE-2024-26309HIGH Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensit | Mar 8, 2024 | 7.5 | 19 | NO | NO |
CVE-2023-45358MEDIUM Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially explo | Oct 17, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-32760MEDIUM An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and | Jul 14, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-30639MEDIUM Archer Platform 6.8 before 6.12 P6 HF1 (6.12.0.6.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability t | May 1, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-49211MEDIUM Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.08. A remote unauthenticated attacker could potentially explo | Oct 22, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-49210MEDIUM Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially exploit thi | Oct 22, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Archer
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2024.03 | 4 | 6.3 | 0.4% | 0 | 0 |