Inflectra develops SpiraTeam, a test-management and requirements-tracking platform deployed in software development environments, with observed vulnerabilities centered on web-application input handling and server-side request issues such as cross-site scripting and SSRF. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inflectra over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48590CRITICAL Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive inform | Mar 20, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-48591MEDIUM Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing. | Mar 20, 2025 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inflectra.
Media articles that mention a CVE ID that affects a product developed by Inflectra — matched by CVE ID, not by vendor name.