Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dialogic

First CVE: Jul 3, 2018Active for: 8 yearsTotal CVEs: 10
52.0
VTI Score
TOP TARGET

Dialogic develops media server and communications platforms, with its vulnerability profile centered on the PowerMedia XMS product line. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through a durable cluster of credential-management, access-control, and input-handling weakness classes including insufficiently protected and hard-coded credentials, CSRF, link-following flaws, and SQL injection, reflecting both the authentication demands and the data-handling surface of a server-side communications system. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
10.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.5
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dialogic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2018
8 years ago
Most Recent CVE
Jul 3, 2018
2,943 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-11641CRITICAL
Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to
Jul 3, 20189.830NONO
CVE-2018-11635CRITICAL
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS thr
Jul 3, 20189.827NONO
CVE-2018-11640CRITICAL
XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files or cause a denial of service (r
Jul 3, 20189.126NONO
CVE-2018-11643HIGH
SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterP
Jul 3, 20188.825NONO
CVE-2018-11636HIGH
Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execute malicious and unauthorized a
Jul 3, 20188.825NONO
CVE-2018-11639HIGH
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows
Jul 3, 20188.123NONO
CVE-2018-11634HIGH
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartex
Jul 3, 20187.823NONO
CVE-2018-11642HIGH
Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root
Jul 3, 20187.822NONO
CVE-2018-11638HIGH
Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to upload malicious code
Jul 3, 20187.222NONO
CVE-2018-11637HIGH
Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to read arbitrary files from the /var/ directory beca
Jul 3, 20187.522NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
70%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local2 (20.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low3 (30.0%)
High1 (10.0%)
None6 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dialogic.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dialogic — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dialogic's Products

View all 1 CNAs →

Top CWEs