Enghouse's vulnerability profile is concentrated in a narrow set of customer-interaction and contact-center platforms, including web chat and unified communications products, where vulnerabilities skew strongly toward critical-severity outcomes. The recurring exposure centers on application-layer input handling and access control, with cross-site scripting, improper input validation, privilege-management flaws, and XML entity injection recurring across the product line—weaknesses typical of web-facing communication platforms that process user-supplied data and manage role-based access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enghouse over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8940CRITICAL ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a | May 14, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-16948CRITICAL An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a | Nov 13, 2019 | 9.8 | 28 | NO | NO |
CVE-2023-45883HIGH A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up windo | Oct 19, 2023 | 7.8 | 23 | NO | NO |
CVE-2019-16950MEDIUM An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript. | Nov 13, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-16949MEDIUM An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the | Nov 13, 2019 | 6.5 | 21 | NO | NO |
CVE-2019-16951MEDIUM A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own domain name. When the product calls this do | Nov 13, 2019 | 5.3 | 19 | NO | NO |
CVE-2020-13972MEDIUM Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the response from the POST request is displayed, and any JavaScr | Sep 3, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enghouse.
Media articles that mention a CVE ID that affects a product developed by Enghouse — matched by CVE ID, not by vendor name.