Knowledgetree Document Management is a document repository and content-management system whose disclosures center on web-application input handling, with cross-site scripting as a recurring weakness class. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Knowledgetree Document Management over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2849HIGH KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory | May 24, 2007 | 10.0 | 25 | NO | NO |
CVE-2008-5857MEDIUM The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboa | Jan 6, 2009 | 6.5 | 17 | NO | NO |
CVE-2008-5858MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a differen | Jan 6, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Knowledgetree Document Management.
Media articles that mention a CVE ID that affects a product developed by Knowledgetree Document Management — matched by CVE ID, not by vendor name.