Hiniarata maintains a specialized web-based case-management plugin product with a narrow but notable footprint in investigative and legal-workflow environments. The vendor's vulnerability profile centers on classic application-layer input-handling weaknesses, including cross-site request forgery and cross-site scripting, that reflect the plugin's role in handling sensitive user interactions and data entry. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hiniarata over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1174HIGH Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators. | Apr 6, 2016 | 8.8 | 27 | NO | NO |
CVE-2016-1172HIGH Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators. | Apr 6, 2016 | 8.8 | 22 | NO | NO |
CVE-2016-1170HIGH Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to hijack the authentication of administrators. | Apr 6, 2016 | 8.8 | 22 | NO | NO |
CVE-2016-1173MEDIUM Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 6, 2016 | 6.1 | 21 | NO | NO |
CVE-2016-1169MEDIUM Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 6, 2016 | 6.1 | 21 | NO | NO |
CVE-2016-1171MEDIUM Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 6, 2016 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hiniarata.
Media articles that mention a CVE ID that affects a product developed by Hiniarata — matched by CVE ID, not by vendor name.