Itpison's vulnerability footprint centers on its OmICard EDM document-management product, with the durable signal concentrated on file-handling and input-validation weaknesses including unrestricted file uploads, path traversal, and SQL injection. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Itpison over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48371CRITICAL ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and | Dec 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-32965CRITICAL OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate | Aug 4, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-32964CRITICAL OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to access, modify, delete database or di | Aug 4, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-48372CRITICAL ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL co | Dec 15, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-32753CRITICAL OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbi | Jun 16, 2023 | 9.8 | 27 | NO | NO |
CVE-2026-10597MEDIUM OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's ema | Jun 4, 2026 | 5.3 | 26 | NO | NO |
CVE-2022-35216HIGH OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access a | Aug 4, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-32963HIGH OMICARD EDM’s mail file relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access ar | Aug 4, 2022 | 7.5 | 24 | NO | NO |
CVE-2023-48373HIGH ITPison OMICARD EDM has a path traversal vulnerability within its parameter “FileName” in a specific function. An unauthenticated remote attacker can exploit this vulnerability to | Dec 15, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-28700MEDIUM OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with administrator privileges can exploit t | Jun 2, 2023 | 6.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Itpison.
Media articles that mention a CVE ID that affects a product developed by Itpison — matched by CVE ID, not by vendor name.