Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Enghouse

First CVE: May 14, 2019Active for: 7 yearsTotal CVEs: 7

Enghouse's vulnerability profile is concentrated in a narrow set of customer-interaction and contact-center platforms, including web chat and unified communications products, where vulnerabilities skew strongly toward critical-severity outcomes. The recurring exposure centers on application-layer input handling and access control, with cross-site scripting, improper input validation, privilege-management flaws, and XML entity injection recurring across the product line—weaknesses typical of web-facing communication platforms that process user-supplied data and manage role-based access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Enghouse over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2019
7 years ago
Most Recent CVE
Oct 19, 2023
1,009 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-8940CRITICAL
ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a
May 14, 20199.830NONO
CVE-2019-16948CRITICAL
An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a
Nov 13, 20199.828NONO
CVE-2023-45883HIGH
A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up windo
Oct 19, 20237.823NONO
CVE-2019-16950MEDIUM
An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript.
Nov 13, 20196.121NONO
CVE-2019-16949MEDIUM
An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the
Nov 13, 20196.521NONO
CVE-2019-16951MEDIUM
A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own domain name. When the product calls this do
Nov 13, 20195.319NONO
CVE-2020-13972MEDIUM
Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the response from the POST request is displayed, and any JavaScr
Sep 3, 20206.117NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
57%
14%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Enghouse.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Enghouse — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Enghouse's Products

View all 1 CNAs →

Top CWEs