Catalystconnect's vulnerability footprint centers on its Zoho CRM client portal product, a web-facing integration layer where the durable signal reflects application-layer input-handling weaknesses, primarily cross-site scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Catalystconnect over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44629MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catalyst Connect Catalyst Connect Zoho CRM Client Portal plugin <= 2.0.0 versions. | Aug 10, 2023 | 4.8 | 17 | NO | NO |
CVE-2023-0588MEDIUM The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cro | Jun 27, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Catalystconnect.
Media articles that mention a CVE ID that affects a product developed by Catalystconnect — matched by CVE ID, not by vendor name.