Gxsoftware's vulnerability footprint centers on XperienceCentral, a web-based content and experience management platform, with the durable signal concentrated on application-layer web security issues including cross-site request forgery, cross-site scripting, input validation failures, and improper output encoding. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gxsoftware over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43710HIGH Interactive Forms (IAF) in GX Software XperienCentral versions 10.31.0 until 10.33.0 was vulnerable to cross site request forgery (CSRF) because the unique token could be deduced u | Jul 26, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-43713HIGH Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data input because form validation could be bypassed. | Jul 26, 2023 | 7.5 | 21 | NO | NO |
CVE-2022-43712MEDIUM POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthorized user is able to bypass othe | Jul 26, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-43711MEDIUM Interactive Forms (IAF) in GX Software XperienCentral versions 10.29.1 until 10.33.0 was vulnerable to cross site scripting attacks (XSS) because the CSP header uses eval() in the | Jul 26, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gxsoftware.
Media articles that mention a CVE ID that affects a product developed by Gxsoftware — matched by CVE ID, not by vendor name.