Pleasantsolutions develops password and credential-management products centered on its Pleasant Password Server, a privileged-access control solution deployed in enterprise environments. The vendor's vulnerability profile reflects application-layer weaknesses recurring across input handling and authorization logic, including cross-site scripting flaws, incorrect authorization checks, and missing access controls typical of web-facing credential platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pleasantsolutions over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27121MEDIUM A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute ar | Oct 4, 2023 | 6.1 | 28 | NO | NO |
CVE-2017-17707HIGH Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password safe entries in Pleasant Password Server before 7.8.3. To per | Jul 31, 2018 | 8.1 | 24 | NO | NO |
CVE-2017-17708MEDIUM Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3. | Jul 31, 2018 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pleasantsolutions.
Media articles that mention a CVE ID that affects a product developed by Pleasantsolutions — matched by CVE ID, not by vendor name.