QPR operates a web-based portal product with a modestly represented but recurring vulnerability pattern centered on cross-site scripting weaknesses in its page-generation and input-handling logic. Current severity, exploitation status, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qpr over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8266MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via t | Feb 1, 2015 | 4.3 | 18 | NO | NO |
CVE-2014-8268MEDIUM QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request. | Feb 1, 2015 | 6.4 | 17 | NO | NO |
CVE-2014-8267MEDIUM Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter. | Feb 1, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qpr.
Media articles that mention a CVE ID that affects a product developed by Qpr — matched by CVE ID, not by vendor name.