Bumsys Project maintains a single web application product that, despite modest volume, occupies a position among the more prominent entities tracked in the vulnerability landscape. The recurring weakness classes—SQL injection, cross-site scripting, cross-site request forgery, PHP remote file inclusion, and external file path control—reflect common input-handling and request-validation gaps endemic to web applications, and the vendor's disclosures frequently acquire public exploit tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bumsys Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0455HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta. | Jan 26, 2023 | 8.8 | 41 | NO | YES |
CVE-2023-2554HIGH External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0. | May 5, 2023 | 7.2 | 38 | NO | NO |
CVE-2023-1362MEDIUM Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2. | Mar 13, 2023 | 6.1 | 31 | NO | YES |
CVE-2023-2551HIGH PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1. | May 5, 2023 | 8.8 | 29 | NO | NO |
CVE-2023-2832HIGH SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0. | May 22, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-1361MEDIUM SQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2. | Mar 13, 2023 | 6.5 | 23 | NO | NO |
CVE-2023-2552HIGH Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1. | May 5, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-2553MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0. | May 5, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bumsys Project.
Media articles that mention a CVE ID that affects a product developed by Bumsys Project — matched by CVE ID, not by vendor name.