Lakernote maintains a narrowly scoped web application platform, EasyAdmin, where its vulnerability profile centers on input-handling and data-access control weaknesses including server-side request forgery, cross-site scripting, XML external entity injection, and path traversal. These recurrent flaws are typical of web application exposure and reflect the parsing and authorization boundaries inherent to admin-facing interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lakernote over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2825HIGH A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315. This affects an unknown part of the file /ureport/designer/saveReportFile. The manipula | Mar 22, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-2828HIGH A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/mod | Mar 22, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-2827HIGH A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing of the file /ureport/designer/sa | Mar 22, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-2826HIGH A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The | Mar 22, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-5383MEDIUM A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation of the a | May 26, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lakernote.
Media articles that mention a CVE ID that affects a product developed by Lakernote — matched by CVE ID, not by vendor name.