Kagilum's vulnerability footprint centers on its icescrum project-management platform, with observed exposures rooted in dynamic code generation and file-path handling—specifically code injection and path-traversal weaknesses characteristic of web applications that process user input to interact with the filesystem or execute logic. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kagilum over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60786HIGH A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip file. | Dec 15, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-60785HIGH A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a crafted HTML page. | Nov 3, 2025 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kagilum.
Media articles that mention a CVE ID that affects a product developed by Kagilum — matched by CVE ID, not by vendor name.