Esafenet's vulnerability footprint centers on a compact set of document security and content management products—including its CDG, DSM, and Electronic Document Security Management System offerings—that handle sensitive information across enterprise workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, with exposure concentrated in input-handling and code-execution weaknesses that recur across the product line: SQL injection, command and code injection, cross-site scripting, and path traversal flaws that reflect the parsing and sanitization demands of document-processing and web-facing interfaces. The vendor occupies a prominent position in the vulnerability landscape despite its narrow product scope, a pattern driven by the severity and breadth of the recurring weakness classes rather than by volume alone. Defenders should treat Esafenet disclosures as high-priority given the criticality bias and apply input-validation and output-encoding patches promptly across the affected product suite; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Esafenet over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9632HIGH ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3 | Mar 8, 2019 | 7.5 | 49 | NO | YES |
CVE-2024-10660CRITICAL A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The | Nov 1, 2024 | 9.8 | 32 | NO | NO |
CVE-2025-2927CRITICAL A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been classified as critical. Affected is an unknown function of the file /parameter/getFileTypeList.jsp. The manipul | Mar 28, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-3400CRITICAL A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. This affects an unknown part of the file /client/UnChkMailApplication.jsp. The | Apr 8, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-3399CRITICAL A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5.6.3.154.205_20250114. Affected by this issue is some unknown functionality of the file /pubinfo/ | Apr 8, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-0791CRITICAL A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The manipulation of | Jan 29, 2025 | 9.8 | 29 | NO | NO |
CVE-2024-10597CRITICAL A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function delPolicyAction of the file /com/esafenet/servlet/system/PolicyActionService.java | Oct 31, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-9536CRITICAL A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The ma | Oct 5, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-1845CRITICAL A vulnerability has been found in ESAFENET DSM 3.1.2 and classified as critical. Affected by this vulnerability is the function examExportPDF of the file /admin/plan/examExportPDF. | Mar 3, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-1841CRITICAL A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the file /CDGServer3/logManagement/ClientSortLog.jsp. The manip | Mar 3, 2025 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Esafenet.
Media articles that mention a CVE ID that affects a product developed by Esafenet — matched by CVE ID, not by vendor name.