Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Extensis

First CVE: Dec 23, 2005Active for: 21 yearsTotal CVEs: 10
52.6
VTI Score
TOP TARGET

Extensis develops a narrowly scoped set of asset-management and digital-publishing products—Portfolio, MrSID, NetPublish Server, and related variants—that serve design and media workflows in creative industries. The vendor's vulnerability signal centers on web-application and file-handling attack surfaces, with recurrent weaknesses in file-upload restrictions, input validation, and cross-site scripting, alongside occasional memory-safety issues; a moderate tendency toward public exploit availability characterizes the disclosed flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Extensis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2005
20 years ago
Most Recent CVE
Mar 1, 2022
1,606 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-3944HIGH
Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via an IMAGE tag.
Jan 2, 20207.838NONO
CVE-2022-24254HIGH
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP fil
Mar 1, 20228.832NONO
CVE-2022-24252HIGH
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.
Mar 1, 20228.831NONO
CVE-2022-24253HIGH
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.
Mar 1, 20228.830NONO
CVE-2022-24251HIGH
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
Mar 1, 20228.830NONO
CVE-2022-24255HIGH
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.
Mar 1, 20228.824NONO
CVE-2005-4510MEDIUM
Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the template parameter.
Dec 23, 20055.023NOYES
CVE-2013-3946HIGH
Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header.
Jan 2, 20207.820NONO
CVE-2013-3945HIGH
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
Jan 2, 20207.820NONO
CVE-2017-18006MEDIUM
netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.
Jan 1, 20186.120NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
20%
80%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (30.0%)
Network6 (60.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None5 (50.0%)
Unknown1 (10.0%)
Required4 (40.0%)
Privileges Required
Low5 (50.0%)
High0 (0.0%)
None4 (40.0%)
Unknown1 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Extensis.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Extensis — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Extensis's Products

View all 1 CNAs →

Top CWEs