Eptura's vulnerability footprint centers on its Archibus workplace and facilities-management platform, a narrowly scoped product that handles sensitive organizational and personnel data. The durable signal reflects application-layer weaknesses spanning information disclosure, path traversal, and SQL injection, typical of web-based administrative systems handling structured data access and file operations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eptura over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25652HIGH In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directory traversal. | Jan 13, 2026 | 7.5 | 25 | NO | NO |
CVE-2023-48645HIGH An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or | Feb 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-48644MEDIUM An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance module, via the description field. Th | Mar 5, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eptura.
Media articles that mention a CVE ID that affects a product developed by Eptura — matched by CVE ID, not by vendor name.