Jitbit develops a narrow line of web-based enterprise applications—a .NET forum platform and helpdesk system—centered on user collaboration and support workflows. The recurring vulnerability signals in these products cluster around web-input handling and cryptographic entropy, reflecting the challenges of sanitizing user-supplied content and maintaining secure session management in multi-user web applications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jitbit over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18486HIGH Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided | Aug 9, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-18636MEDIUM A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parame | Nov 1, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jitbit.
Media articles that mention a CVE ID that affects a product developed by Jitbit — matched by CVE ID, not by vendor name.