Exceedone develops web-based administrative and business-process platforms, with its vulnerability footprint centered on products such as Exment and Laravel Admin that handle data management and access control. The durable signal across its disclosures reflects application-layer input handling and access-control weaknesses, including cross-site scripting, SQL injection, and improper permission assignment, typical of web frameworks that directly expose user-interaction surfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exceedone over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37333HIGH SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and | Aug 24, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-38089MEDIUM Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and e | Aug 24, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-38080MEDIUM Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 an | Aug 24, 2022 | 5.4 | 20 | NO | NO |
CVE-2020-5620MEDIUM Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file. | Aug 25, 2020 | 5.4 | 20 | NO | NO |
CVE-2024-47793MEDIUM Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When accessing the edit screen containing custom columns (column type: | Oct 18, 2024 | 5.4 | 17 | NO | NO |
CVE-2020-5619MEDIUM Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via unspecified vectors. | Aug 25, 2020 | 5.4 | 15 | NO | NO |
Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in user with the permission of table manage | Oct 18, 2024 | 3.8 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exceedone.
Media articles that mention a CVE ID that affects a product developed by Exceedone — matched by CVE ID, not by vendor name.