Ovidentia is a niche collaboration and knowledge-management platform whose vulnerability profile concentrates in a single application product and centers durably on web-application input handling and file-management weaknesses. The recurring exposure spans SQL injection, cross-site scripting, path traversal, and unrestricted file upload flaws—all characteristic of application-layer trust and validation boundaries—and the vendor's disclosures frequently acquire public exploit code. Defenders deploying this platform should prioritize input-validation and file-handling patches; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ovidentia over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3918HIGH SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action. NOTE: the provena | Sep 4, 2008 | 7.5 | 30 | NO | YES |
CVE-2019-13977MEDIUM index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Cre | Jul 19, 2019 | 5.4 | 29 | NO | YES |
CVE-2019-13978HIGH Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request. | Jul 19, 2019 | 8.8 | 27 | NO | NO |
CVE-2022-22914HIGH An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path | Feb 17, 2022 | 7.5 | 26 | NO | NO |
CVE-2018-1000619HIGH Ovidentia version 8.4.3 and earlier contains a Unsanitized User Input vulnerability in utilit.php, bab_getAddonFilePathfromTg that can result in Authenticated Remote Code Execution | Jul 9, 2018 | 8.8 | 26 | NO | NO |
CVE-2008-4423MEDIUM SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the item parameter in a contact modify action. | Oct 3, 2008 | 6.5 | 25 | NO | YES |
CVE-2008-3917MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter in a search action. | Sep 4, 2008 | 4.3 | 21 | NO | YES |
CVE-2021-29343MEDIUM Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text reg | Mar 30, 2021 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ovidentia.
Media articles that mention a CVE ID that affects a product developed by Ovidentia — matched by CVE ID, not by vendor name.