Axiell develops library and cultural heritage management software, with its Iguana product serving institutions managing collections and public access systems. The recurring vulnerability signal centers on web-facing input-handling weaknesses, specifically cross-site scripting and improper exposure of files and directories, characteristic of web applications that mediate public interaction with institutional data; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Axiell over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45052MEDIUM A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, exte | Jan 4, 2023 | 6.5 | 23 | NO | NO |
CVE-2022-45051MEDIUM A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The module parameter on the Service.template.cls endp | Jan 4, 2023 | 6.1 | 22 | NO | NO |
CVE-2022-45050MEDIUM A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The title parameter on the twitter.php endpoint does | Dec 1, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-45049MEDIUM A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The url parameter on the novelist.php endpoint does n | Jan 4, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Axiell.
Media articles that mention a CVE ID that affects a product developed by Axiell — matched by CVE ID, not by vendor name.