Gespage is a modestly represented messaging and communication platform whose vulnerability footprint concentrates around a single product line. The recurring exposure centers on application-layer input-handling weaknesses, including cross-site scripting, path traversal, and SQL injection, reflecting the web-facing nature of the platform. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gespage over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7997CRITICAL Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or | Jan 8, 2018 | 9.8 | 52 | NO | YES |
CVE-2021-33807HIGH Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData. | Jul 12, 2021 | 7.5 | 42 | NO | YES |
CVE-2017-7998MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a pri | Jan 8, 2018 | 6.1 | 22 | NO | NO |
CVE-2018-9147MEDIUM Cross-site scripting (XSS) vulnerabilities in version 7.5.7 of Gespage software allow remote attackers to inject arbitrary web script or HTML via the email, passwd, and repasswd pa | Mar 30, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gespage.
Media articles that mention a CVE ID that affects a product developed by Gespage — matched by CVE ID, not by vendor name.