Publisure is a focused document-management and publishing platform where the durable vulnerability signal centers on application-layer security gaps including SQL injection, missing authentication controls, and unrestricted file uploads. These weakness classes reflect the input-handling and access-control requirements of web-facing document platforms; treat this as a compact vendor profile rather than a broad trend line. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Publisure over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14254CRITICAL An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL injections in userAccFunctions.php functions. Us | Sep 18, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-14252HIGH An issue was discovered in the secure portal in Publisure 2.1.2. Once successfully authenticated as an administrator, one is able to inject arbitrary PHP code by using the adminCon | Sep 18, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-14253MEDIUM An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and perform a query on PHP forms within the /AdminDir folder tha | Sep 18, 2019 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Publisure.
Media articles that mention a CVE ID that affects a product developed by Publisure — matched by CVE ID, not by vendor name.