Egavilanmedia's vulnerability profile centers on a modest portfolio of web-based business applications including user registration, expense management, and address-book systems that serve administrative and operational functions. The vendor's disclosures skew strongly toward critical-severity outcomes and recur through application-layer input-handling weaknesses: SQL injection, cross-site scripting, and cross-site request forgery are characteristic of web applications with insufficient input validation and output encoding. Defenders should prioritize patches for this vendor's administrative and data-facing products and apply defense-in-depth validation controls; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Egavilanmedia over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35276CRITICAL EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user. | Dec 21, 2020 | 9.8 | 33 | NO | NO |
CVE-2021-44096CRITICAL EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-44098CRITICAL EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database. | Jun 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-29474CRITICAL EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrar | Dec 24, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-29472CRITICAL EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perf | Dec 24, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-35263CRITICAL EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution. | Jan 26, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-35273HIGH EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attac | Dec 21, 2020 | 8.0 | 26 | NO | NO |
CVE-2020-29228HIGH EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page. | Dec 30, 2020 | 7.5 | 21 | NO | NO |
CVE-2020-29231MEDIUM EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the atta | Dec 30, 2020 | 5.4 | 20 | NO | NO |
CVE-2020-35252MEDIUM Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0. | Dec 23, 2020 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Egavilanmedia.
Media articles that mention a CVE ID that affects a product developed by Egavilanmedia — matched by CVE ID, not by vendor name.