Atisoluciones develops web-based business management software, with its CIGES product forming the core of the observed vulnerability footprint. The recurring exposure centers on application-layer input-handling weaknesses—SQL injection, cross-site scripting, and sensitive-data exposure—that are characteristic of web applications where input validation and output encoding demand careful design. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atisoluciones over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2722HIGH SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve | Mar 22, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-2724HIGH SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote us | Mar 22, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-2725HIGH Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the | Mar 22, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-2723HIGH SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to | Mar 22, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-2727MEDIUM HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify elements of the website and email confirmation message. | Mar 22, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-2726MEDIUM Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and store malicious javascript code in the application form wit | Mar 22, 2024 | 6.1 | 19 | NO | NO |
A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected condi | Nov 24, 2025 | 2.7 | 15 | NO | NO |
CVE-2024-2728MEDIUM Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept traffic due to the lack of proper implementation of the TLS p | Mar 22, 2024 | 5.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atisoluciones.
Media articles that mention a CVE ID that affects a product developed by Atisoluciones — matched by CVE ID, not by vendor name.