Hennessey appears to be a legal or professional services platform, with its tracked vulnerability footprint centering on the Attorney product and reflecting application-level input-handling and access-control issues such as cross-site scripting and missing authorization. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hennessey over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45832CRITICAL Missing Authorization vulnerability in Hennessey Digital Attorney.This issue affects Attorney: from n/a through 3. | Jun 19, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-41692MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hennessey Digital Attorney theme <= 3 theme. | Oct 2, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hennessey.
Media articles that mention a CVE ID that affects a product developed by Hennessey — matched by CVE ID, not by vendor name.