Eramba is a governance, risk, and compliance platform whose vulnerability profile concentrates in its core application and reflects the input-handling and code-generation demands of a web-based policy and control framework. The recurring weakness classes—cross-site scripting, code injection, improper input validation, and related injection vectors—cluster around the application's handling of user-supplied data and policy configurations, with a meaningful share reaching serious severity and a moderate tendency toward public exploit availability. Defenders should prioritize patches to this platform given its role in managing security controls and risk posture; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eramba over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36255HIGH An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL. | Aug 3, 2023 | 8.8 | 66 | NO | YES |
CVE-2025-55462MEDIUM A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in the Access-Control-Allow-Origin response | Jan 13, 2026 | 6.5 | 28 | NO | NO |
CVE-2020-25105CRITICAL eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities). | Sep 3, 2020 | 9.8 | 28 | NO | NO |
CVE-2018-7997MEDIUM Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file polluted with malicious JavaScript. | Mar 9, 2018 | 6.1 | 21 | NO | NO |
CVE-2022-43342MEDIUM A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload | Nov 14, 2022 | 5.4 | 20 | NO | NO |
CVE-2018-7996MEDIUM Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter. | Mar 9, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-7894MEDIUM Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter). | Mar 9, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-7741MEDIUM Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI. | Mar 7, 2018 | 6.1 | 20 | NO | NO |
CVE-2020-25104MEDIUM eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the | Sep 3, 2020 | 5.4 | 18 | NO | NO |
CVE-2020-28031MEDIUM eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users. | Nov 2, 2020 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eramba.
Media articles that mention a CVE ID that affects a product developed by Eramba — matched by CVE ID, not by vendor name.