Karaz maintains a narrowly scoped product portfolio centered on Karazal, with its documented vulnerabilities clustering around cross-site scripting weaknesses in web page generation. This represents a compact vendor profile focused on input-handling security in web application contexts; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Karaz over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-46657MEDIUM Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI. | Apr 27, 2025 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Karaz.
Media articles that mention a CVE ID that affects a product developed by Karaz — matched by CVE ID, not by vendor name.