Marmotech's vulnerability footprint centers on the Kados product, a narrowly scoped offering that has attracted disproportionate attention in the vulnerability landscape relative to its product breadth. The vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through SQL injection weaknesses, reflecting input-handling and query-construction patterns characteristic of database-connected applications. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marmotech over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25704CRITICAL Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. Attack | Apr 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25702CRITICAL Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers ca | Apr 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25700CRITICAL Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attacker | Apr 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25698CRITICAL Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers | Apr 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25694CRITICAL Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset paramet | Apr 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25692CRITICAL Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attacker | Apr 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25696CRITICAL Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers | Apr 5, 2026 | 9.1 | 28 | NO | NO |
CVE-2019-25688CRITICAL Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 paramete | Apr 5, 2026 | 9.1 | 28 | NO | NO |
CVE-2019-25690HIGH Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attacker | Apr 5, 2026 | 8.2 | 26 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marmotech.
Media articles that mention a CVE ID that affects a product developed by Marmotech — matched by CVE ID, not by vendor name.