Gleamtech develops a small portfolio of web-based file-management and sharing applications, primarily FileVista and FileUltimate, that expose user data and system access to input-handling and authorization weaknesses. The recurring vulnerability patterns center on information disclosure, improper access control, path traversal, cross-site scripting, and input-validation flaws characteristic of web applications handling file operations and user permissions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gleamtech over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-57248MEDIUM Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Information Disclosure, and Escalation of Privileges via inject | Feb 7, 2025 | 6.3 | 20 | NO | NO |
CVE-2024-57249MEDIUM Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control | Feb 7, 2025 | 6.5 | 19 | NO | NO |
CVE-2014-8789MEDIUM GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in a zip archive, which is not pro | Dec 2, 2014 | 6.5 | 18 | NO | NO |
CVE-2020-15015MEDIUM The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document. | Jun 24, 2020 | 6.1 | 17 | NO | NO |
CVE-2014-8788MEDIUM GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when saving a zip file, which reveals the installation path in a | Dec 2, 2014 | 4.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gleamtech.
Media articles that mention a CVE ID that affects a product developed by Gleamtech — matched by CVE ID, not by vendor name.