Dradisframework maintains a specialized vulnerability-disclosure and collaboration platform used by security teams, with a narrowly scoped product footprint centered on the Dradis application itself. The recurring vulnerability signal reflects the platform's role as a web-facing, multi-user system: weaknesses cluster around input-handling and output-encoding issues such as cross-site scripting, authentication and authorization bypass conditions, race conditions in shared resource access, and sensitive information exposure through metadata. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dradisframework over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30028MEDIUM Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token. | Jun 24, 2022 | 5.9 | 21 | NO | NO |
CVE-2023-31223MEDIUM Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars. | Apr 25, 2023 | 5.4 | 20 | NO | NO |
CVE-2019-19946MEDIUM The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team. | Mar 16, 2020 | 6.5 | 20 | NO | NO |
CVE-2019-5925MEDIUM Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authentica | Mar 12, 2019 | 5.4 | 20 | NO | NO |
CVE-2023-50458MEDIUM In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs. | Jul 10, 2025 | 4.3 | 15 | NO | NO |
CVE-2023-50786MEDIUM Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized au | Jul 5, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dradisframework.
Media articles that mention a CVE ID that affects a product developed by Dradisframework — matched by CVE ID, not by vendor name.