Hortusfox is a niche web-based horticultural management application whose vulnerability profile centers on a single product with recurring input-handling issues. The disclosed weaknesses cluster around cross-site scripting and command-injection flaws characteristic of web applications where user input reaches template generation and system execution paths. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hortusfox over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-45313MEDIUM A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a cr | Aug 13, 2025 | 6.1 | 24 | NO | NO |
CVE-2025-45314MEDIUM A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a | Aug 13, 2025 | 6.1 | 23 | NO | NO |
CVE-2025-45317MEDIUM A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted archive. | Aug 13, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-45315MEDIUM A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's b | Aug 13, 2025 | 5.4 | 22 | NO | NO |
CVE-2025-45316MEDIUM A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary web scripts or HTML via injecting a craf | Aug 13, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-57329MEDIUM HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execu | Jan 23, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hortusfox.
Media articles that mention a CVE ID that affects a product developed by Hortusfox — matched by CVE ID, not by vendor name.