Jaba operates a narrowly scoped product portfolio centered on its Xpress offering. The vendor's vulnerability signal centers on file-upload handling, with exposure rooted in improper validation of uploaded file types, a weakness class that reflects the product's document or content-management orientation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jaba over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17058HIGH An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An auth | Mar 2, 2020 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jaba.
Media articles that mention a CVE ID that affects a product developed by Jaba — matched by CVE ID, not by vendor name.