Dext5 is a narrowly scoped document processing and file-handling platform whose vulnerability profile skews strongly toward critical-severity outcomes across its core upload, editor, and document-conversion products. The recurring weakness classes—unrestricted file uploads, integrity-unchecked code downloads, input validation gaps, path traversal, and default-permission misconfigurations—reflect the inherent risks of accepting and processing untrusted user content without strict validation and containment. Defenders should treat Dext5 instances as high-risk, particularly where they accept external documents or user-supplied files; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dext5 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7832CRITICAL A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectIt | Sep 7, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-7875HIGH DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the | Oct 28, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-13894HIGH handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field. | Jun 7, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-13442CRITICAL A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file i | May 25, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-7864CRITICAL Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz DEXT5Editor versions prior to 3. | Jun 15, 2021 | 9.8 | 24 | NO | NO |
CVE-2020-35362HIGH DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest ac | Dec 26, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dext5.
Media articles that mention a CVE ID that affects a product developed by Dext5 — matched by CVE ID, not by vendor name.