Clipsoft's vulnerability footprint centers on its Rexpert product, a narrowly scoped offering that carries a durable signal around file-handling and input-validation weaknesses. The recurring exposure reflects path-traversal, unrestricted file upload, XML injection, and information-disclosure classes typical of applications processing untrusted user input and file submissions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clipsoft over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17323HIGH ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. User interaction | Oct 30, 2019 | 8.8 | 25 | NO | NO |
CVE-2019-17326MEDIUM ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET request with a specially crafted parameter. User interaction | Oct 30, 2019 | 6.5 | 21 | NO | NO |
CVE-2019-17325MEDIUM ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of | Oct 30, 2019 | 6.5 | 21 | NO | NO |
CVE-2019-17324MEDIUM ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, | Oct 30, 2019 | 6.5 | 21 | NO | NO |
CVE-2019-17322MEDIUM ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable fi | Oct 30, 2019 | 6.5 | 21 | NO | NO |
CVE-2019-17321MEDIUM ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of | Oct 30, 2019 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clipsoft.
Media articles that mention a CVE ID that affects a product developed by Clipsoft — matched by CVE ID, not by vendor name.