Primakon develops project and contract management software serving a specialized but critical business function, and its vulnerability profile concentrates on authorization and access-control weaknesses across its core product line. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, while exposure recurs through weakness classes including improper authorization, access-control bypass conditions, and unintended exposure of sensitive system information—patterns characteristic of business-logic flaws in multi-user enterprise applications. Defenders should prioritize updates for this vendor given the sensitive nature of contract and project data; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Primakon over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64063CRITICAL Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending dir | Nov 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-64065HIGH The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vul | Nov 25, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-64064HIGH Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of we | Nov 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-64066HIGH Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing | Nov 25, 2025 | 8.6 | 27 | NO | NO |
CVE-2025-64062HIGH The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipula | Nov 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-64067MEDIUM Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side | Nov 25, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-64061MEDIUM Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their | Nov 25, 2025 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Primakon.
Media articles that mention a CVE ID that affects a product developed by Primakon — matched by CVE ID, not by vendor name.