Dolusoft's vulnerability profile centers on its OMASpot product, a web-facing application where disclosures cluster around data-protection and input-handling weaknesses including cleartext transmission of sensitive information, cross-site scripting, and SQL injection. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dolusoft over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-7744CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dolusoft Omaspot allows SQL Injection.
This issue affects Omaspot: before 12. | Sep 16, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-7743CRITICAL Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation.
This issue affects Omaspot: before 12.09.2025. | Sep 16, 2025 | 9.6 | 29 | NO | NO |
CVE-2025-6575MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dolusoft Omaspot allows Reflected XSS.
This issue affects Omaspot: bef | Sep 16, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dolusoft.
Media articles that mention a CVE ID that affects a product developed by Dolusoft — matched by CVE ID, not by vendor name.