Diskoverdata's vulnerability footprint centers on its Diskover data intelligence and file analytics platform, with the recurring signal focused on application-layer input-handling weaknesses including cross-site scripting and SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Diskoverdata over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50984MEDIUM diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsanitized user input in POST para | Aug 27, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-50986MEDIUM diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields | Aug 27, 2025 | 5.6 | 20 | NO | NO |
CVE-2025-50985MEDIUM diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxind | Aug 27, 2025 | 5.6 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Diskoverdata.
Media articles that mention a CVE ID that affects a product developed by Diskoverdata — matched by CVE ID, not by vendor name.