Bonitasoft develops a business process management platform centered on its Bonita BPM portal and web components, deployed in enterprise workflow and automation environments. The vendor's disclosed vulnerabilities cluster around web-application input handling and URI control, with recurrent issues including path traversal, cross-site scripting, XML external entity injection, and open redirects that reflect the attack surface of browser-facing process-management interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bonitasoft over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25237CRITICAL Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i1 | Jun 2, 2022 | 9.8 | 73 | NO | YES |
CVE-2015-3897MEDIUM Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the | Jun 18, 2015 | 5.0 | 38 | NO | YES |
CVE-2020-36640CRITICAL A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException o | Jan 5, 2023 | 9.8 | 31 | NO | NO |
CVE-2015-3898MEDIUM Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors in | Feb 28, 2018 | 6.1 | 27 | NO | YES |
CVE-2024-26542MEDIUM Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrary code via a crafted payload to the Gr | Feb 27, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bonitasoft.
Media articles that mention a CVE ID that affects a product developed by Bonitasoft — matched by CVE ID, not by vendor name.