Gss develops a focused portfolio of enterprise social platforms and analytics products, including VitalsESP, IOTA C.AI, and Vitals Enterprise Social Platform, serving specialized business and data integration use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across input-handling and authentication boundaries through weakness classes such as SQL injection, absolute path traversal, code injection, improper cryptographic signature verification, and incorrect authorization. Defenders tracking this vendor should prioritize patching of its platforms, particularly where they expose integration or administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gss over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4639HIGH Vitals ESP developed by Galaxy Software Services has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to perform certain administrative functions, t | Mar 24, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-4640HIGH Vitals ESP developed by Galaxy Software Services has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to execute certain functions to obtain sensit | Mar 24, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-37291CRITICAL Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vul | Jul 21, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-41357HIGH Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated rem | Nov 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-14255MEDIUM Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database conten | Dec 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-14254MEDIUM Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database conten | Dec 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-52959HIGH A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authentic | Nov 27, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-52958HIGH A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated user | Nov 27, 2024 | 7.2 | 20 | NO | NO |
CVE-2025-14253MEDIUM Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbit | Dec 8, 2025 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gss.
Media articles that mention a CVE ID that affects a product developed by Gss — matched by CVE ID, not by vendor name.