Bigprof develops a focused suite of web-based business management applications, including online invoicing, clinic management, and the AppGini low-code platform, which serve small- to medium-sized organizations. The vendor's vulnerability disclosures concentrate on application-layer input handling and request validation, with recurring weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and CSV formula injection that are characteristic of web applications built without comprehensive input-sanitization and CSRF-token discipline. Despite the modest product footprint, the vendor's presence in the top decile of the vulnerability landscape reflects the widespread deployment and accessibility of web-facing business applications, where these weakness classes can directly threaten data confidentiality and business continuity. Defenders should prioritize patching cycles for exposed instances of these products and enforce input validation and request-origin controls at both the application and network layer. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bigprof over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35674CRITICAL BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-s | Sep 29, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-35675HIGH BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTran | Sep 29, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-35676MEDIUM BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration functionality. As such, an attacker can inpu | Dec 24, 2020 | 6.1 | 21 | NO | NO |
CVE-2023-6435MEDIUM A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory | Nov 30, 2023 | 5.4 | 19 | NO | NO |
CVE-2018-18587MEDIUM BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash. | Oct 23, 2018 | 5.3 | 19 | NO | NO |
CVE-2023-6434MEDIUM A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory | Nov 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-6433MEDIUM A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory | Nov 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-6427MEDIUM A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicing | Nov 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-6426MEDIUM A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /invoicing | Nov 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-6425MEDIUM A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /c | Nov 30, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bigprof.
Media articles that mention a CVE ID that affects a product developed by Bigprof — matched by CVE ID, not by vendor name.