Quipux operates a document-management and workflow platform that handles sensitive organizational data, and its disclosed vulnerabilities center on application-layer input handling and data exposure. The recurring weakness classes—including cross-site scripting, SQL injection, improper input neutralization, and sensitive information exposure—reflect the challenges of securing web-facing forms and database queries in systems that process confidential records. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quipux over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55343CRITICAL Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista. | Nov 5, 2025 | 9.9 | 31 | NO | NO |
CVE-2025-55341MEDIUM Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad. | Nov 5, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-55342MEDIUM Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_pa | Nov 5, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quipux.
Media articles that mention a CVE ID that affects a product developed by Quipux — matched by CVE ID, not by vendor name.