Extensis develops a narrowly scoped set of asset-management and digital-publishing products—Portfolio, MrSID, NetPublish Server, and related variants—that serve design and media workflows in creative industries. The vendor's vulnerability signal centers on web-application and file-handling attack surfaces, with recurrent weaknesses in file-upload restrictions, input validation, and cross-site scripting, alongside occasional memory-safety issues; a moderate tendency toward public exploit availability characterizes the disclosed flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Extensis over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3944HIGH Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via an IMAGE tag. | Jan 2, 2020 | 7.8 | 38 | NO | NO |
CVE-2022-24254HIGH An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP fil | Mar 1, 2022 | 8.8 | 32 | NO | NO |
CVE-2022-24252HIGH An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file. | Mar 1, 2022 | 8.8 | 31 | NO | NO |
CVE-2022-24253HIGH Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet. | Mar 1, 2022 | 8.8 | 30 | NO | NO |
CVE-2022-24251HIGH Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function. | Mar 1, 2022 | 8.8 | 30 | NO | NO |
CVE-2022-24255HIGH Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges. | Mar 1, 2022 | 8.8 | 24 | NO | NO |
CVE-2005-4510MEDIUM Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the template parameter. | Dec 23, 2005 | 5.0 | 23 | NO | YES |
CVE-2013-3946HIGH Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header. | Jan 2, 2020 | 7.8 | 20 | NO | NO |
CVE-2013-3945HIGH The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag. | Jan 2, 2020 | 7.8 | 20 | NO | NO |
CVE-2017-18006MEDIUM netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447. | Jan 1, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Extensis.
Media articles that mention a CVE ID that affects a product developed by Extensis — matched by CVE ID, not by vendor name.