Intranda develops Goobi Viewer Core, a specialized digital library and content-management platform, with reported vulnerabilities centered on web-application input handling. The durable exposure reflects cross-site scripting and path-traversal weaknesses typical of web interfaces that process user-supplied content and file paths, areas where robust input sanitization and directory restriction are critical to defense. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intranda over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29016MEDIUM The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in Goobi viewer core | Apr 6, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-29015MEDIUM The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A cross-site scripting vulnerability has been identified in the user comment | Apr 6, 2023 | 6.1 | 20 | NO | NO |
CVE-2020-15124MEDIUM In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files ac | Jul 22, 2020 | 6.5 | 18 | NO | NO |
CVE-2023-29014MEDIUM The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. A reflected cross-site scripting vulnerability has been identified in Goobi v | Apr 6, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intranda.
Media articles that mention a CVE ID that affects a product developed by Intranda — matched by CVE ID, not by vendor name.