Manydesigns develops Portofino, a web application framework and rapid-development platform for business applications, with a small but established footprint in the vulnerability record centered on resource-access and cryptographic-validation weaknesses. The recurring exposure involves improper verification of cryptographic signatures, exposure of resources to wrong security spheres, and insecure temporary-file handling, typical of application frameworks where access control and credential-handling boundaries require careful enforcement. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Manydesigns over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29451CRITICAL Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens. This allows forging a valid JWT. The | Apr 16, 2021 | 9.1 | 29 | NO | NO |
CVE-2022-3952HIGH A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerability is the function createTempDir of the file WarFileLaunche | Nov 11, 2022 | 7.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Manydesigns.
Media articles that mention a CVE ID that affects a product developed by Manydesigns — matched by CVE ID, not by vendor name.