Economizzer's vulnerability profile centers on a single financial management and budgeting application, with disclosures that skew toward serious severity outcomes. The recurrent weakness classes—authorization bypass through user-controlled keys, code injection, SQL injection, clickjacking, and observable discrepancies—reflect the web-application attack surface inherent to credential and transaction handling in a personal-finance tool. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Economizzer over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38874HIGH A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A malicious attacker can upload | Sep 28, 2023 | 8.8 | 39 | NO | NO |
CVE-2023-38870CRITICAL A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'ca | Sep 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-38877HIGH A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password r | Sep 28, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-38873MEDIUM The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI redress attack", is when an attacker uses mul | Sep 28, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-38871MEDIUM The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differen | Sep 28, 2023 | 5.3 | 18 | NO | NO |
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book e | Sep 28, 2023 | 3.7 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Economizzer.
Media articles that mention a CVE ID that affects a product developed by Economizzer — matched by CVE ID, not by vendor name.