Mayswind develops a focused personal finance management application, EZBookkeeping, with a modest vulnerability footprint centered on access control and input-handling weaknesses. The observed weakness classes—improper interaction-frequency controls, incorrect default permissions, and uncontrolled recursion—reflect common challenges in web application design where authentication, configuration defaults, and resource consumption require careful defense. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mayswind over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-57604CRITICAL An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component. | Feb 12, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-65519MEDIUM mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processing. The application fails to validate nesting depth during pa | Feb 18, 2026 | 6.5 | 22 | NO | NO |
CVE-2024-57603MEDIUM An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting. | Feb 12, 2025 | 6.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mayswind.
Media articles that mention a CVE ID that affects a product developed by Mayswind — matched by CVE ID, not by vendor name.