Boodskap develops IoT and blockchain-oriented platforms, including its IoT Platform and GrowChain product line, serving connectivity and data-management use cases in constrained and embedded environments. Its observed vulnerability landscape concentrates on authentication and input-handling weaknesses, including improper authentication mechanisms, cross-site scripting, integer overflows, and missing authentication for critical functions—issues endemic to web-interfaced IoT systems where authentication layers and input validation are foundational. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boodskap over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35135HIGH Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>. | Oct 13, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-13325HIGH The _sell function of a smart contract implementation for GROWCHAIN (GROW), an Ethereum token, has an integer overflow. | Jul 5, 2018 | 7.5 | 22 | NO | NO |
CVE-2022-35134MEDIUM Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability. | Oct 13, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-35136MEDIUM Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests. | Oct 13, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boodskap.
Media articles that mention a CVE ID that affects a product developed by Boodskap — matched by CVE ID, not by vendor name.