Nchsoftware maintains a narrowly scoped product portfolio focused on business communications, accounting, and customer relationship tools such as Axon PBX, Quorum, IVM Attendant, Express Invoice, and Express Accounts. The vendor's vulnerability profile concentrates on application-layer and data-handling weaknesses, with recurring exposure to cross-site scripting, path traversal, forced browsing, cleartext credential storage, and insufficiently protected authentication secrets—patterns characteristic of web-facing business applications that prioritize feature velocity over defense-in-depth. These weakness classes reflect common architectural shortfalls in input validation, access control, and credential hygiene rather than memory-safety or complex system-level flaws, and they tend to affect multiple products across the vendor's portfolio. Defenders should focus remediation on web-tier hardening and credential rotation for this vendor's affected tools; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nchsoftware over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2894HIGH Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) | Jun 27, 2008 | 9.3 | 33 | NO | YES |
CVE-2020-11560HIGH NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. | Apr 7, 2020 | 7.8 | 28 | NO | YES |
CVE-2021-37444HIGH NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname | Jul 25, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-37447HIGH In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion. | Jul 25, 2021 | 8.1 | 25 | NO | NO |
CVE-2021-37443HIGH NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion. | Jul 25, 2021 | 8.1 | 25 | NO | NO |
CVE-2021-37445MEDIUM In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading. | Jul 25, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-37442MEDIUM NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files. | Jul 25, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-11561HIGH In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen. | Apr 7, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-13474MEDIUM In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users. | Dec 28, 2020 | 6.5 | 21 | NO | NO |
CVE-2021-37449MEDIUM Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected). | Jul 25, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nchsoftware.
Media articles that mention a CVE ID that affects a product developed by Nchsoftware — matched by CVE ID, not by vendor name.