Archerydms develops the Archery document management system, a narrowly scoped but notably prominent offering in its segment. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through SQL injection and hard-coded credential weaknesses that are characteristic of legacy credential and data-handling logic. Defenders should prioritize patches for this vendor's disclosures given the severity profile and the system's typical role in managing sensitive documents; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Archerydms over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38542CRITICAL Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, plea | Sep 13, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-38541CRITICAL Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface. | Sep 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-38540CRITICAL Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface. | Sep 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-38539CRITICAL Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply. | Sep 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-38537CRITICAL Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql inter | Sep 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-38538CRITICAL Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module. | Sep 13, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-30558MEDIUM Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. User | Apr 19, 2023 | 6.5 | 23 | NO | NO |
CVE-2023-30557MEDIUM Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affe | Apr 19, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-30556MEDIUM Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases. Affe | Apr 19, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-30555MEDIUM Archery is an open source SQL audit platform. The Archery project contains multiple SQL injection vulnerabilities, that may allow an attacker to query the connected databases.Affec | Apr 19, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Archerydms.
Media articles that mention a CVE ID that affects a product developed by Archerydms — matched by CVE ID, not by vendor name.