Landray develops enterprise workflow and document management platforms, chiefly the EKP and Office Automation products, which handle sensitive organizational data and user input at scale. The observed vulnerability pattern centers on path-traversal conditions, cleartext storage of credentials and sensitive information, and cross-site scripting flaws typical of web-based enterprise applications where input validation and access-control boundaries require close attention. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Landray over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11238MEDIUM A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent | Nov 15, 2024 | 5.3 | 29 | NO | YES |
CVE-2022-34924HIGH Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp. | Aug 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-3159MEDIUM A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.9.R.20160325 allows attackers to execute arbitrary web scrip | Jul 23, 2021 | 5.4 | 20 | NO | NO |
CVE-2024-11239MEDIUM A vulnerability has been found in Landray EKP up to 16.0 and classified as critical. This vulnerability affects the function deleteFile of the file /sys/common/import.do?method=del | Nov 15, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Landray.
Media articles that mention a CVE ID that affects a product developed by Landray — matched by CVE ID, not by vendor name.