Bladex develops a focused product line centered on the Springblade platform, which occupies a more prominent position in the vulnerability landscape than its narrow scope might suggest. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through SQL injection, access-control failures, and resource-exposure flaws that reflect the authentication and data-handling demands of web-facing applications. Defenders should prioritize this vendor's security advisories and maintain current patching posture; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bladex over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40787CRITICAL In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | Aug 29, 2023 | 9.8 | 38 | NO | NO |
CVE-2025-70983CRITICAL Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges. | Jan 23, 2026 | 9.9 | 34 | NO | NO |
CVE-2025-70982CRITICAL Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data. | Jan 26, 2026 | 9.9 | 32 | NO | NO |
CVE-2023-47458CRITICAL An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework. | Jan 2, 2024 | 9.8 | 30 | NO | NO |
CVE-2020-16165CRITICAL The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters. | Jul 30, 2020 | 9.8 | 30 | NO | NO |
CVE-2024-8023CRITICAL A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manip | Aug 21, 2024 | 9.8 | 25 | NO | NO |
CVE-2022-27360CRITICAL SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. | May 5, 2022 | 9.8 | 24 | NO | NO |
CVE-2024-33332HIGH An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant. | Apr 30, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-40788MEDIUM SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs | Sep 19, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bladex.
Media articles that mention a CVE ID that affects a product developed by Bladex — matched by CVE ID, not by vendor name.