Maggioli operates a niche procurement and contract management platform (Appalti & Contratti) primarily serving Italian public administration and enterprise procurement workflows. The vulnerability profile centers on application-layer input handling and authentication controls, with recurring exposure in PHP remote file inclusion, cross-site scripting, SQL injection, and missing authentication for critical functions—patterns typical of web-facing systems with evolving security practices. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maggioli over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44785CRITICAL An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthent | Nov 21, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-44784HIGH An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of services provided by the Axis 1.4 instance, embedded directly into | Nov 21, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-44786HIGH An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href parameter to specify the JSP page to b | Nov 21, 2022 | 7.5 | 23 | NO | NO |
CVE-2022-44787MEDIUM An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scripting issue. The idPagina parameter is reflected inside the | Nov 21, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-44788MEDIUM An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit | Nov 21, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maggioli.
Media articles that mention a CVE ID that affects a product developed by Maggioli — matched by CVE ID, not by vendor name.