Ragic operates a cloud-based database and application platform targeted at enterprise users, where its modest but visible vulnerability footprint concentrates on web application and data-access tiers. The recurring exposure centers on input-handling and authentication weaknesses—including cross-site scripting, path traversal, unrestricted file uploads, and missing authentication for critical functions—that are characteristic of database-as-a-service platforms where user input flows directly into data storage and retrieval workflows. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting the sensitivity of cloud database access and the direct path from application logic to business data; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ragic over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15016CRITICAL Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verifi | Dec 22, 2025 | 9.8 | 35 | NO | NO |
CVE-2024-9985CRITICAL Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary c | Oct 15, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-9984CRITICAL Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user' | Oct 15, 2024 | 9.8 | 30 | NO | NO |
CVE-2025-15015HIGH Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbit | Dec 22, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-9983HIGH Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary | Oct 15, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-40739MEDIUM Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross- | Oct 31, 2022 | 5.4 | 21 | NO | NO |
CVE-2023-41343MEDIUM Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to p | Nov 3, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ragic.
Media articles that mention a CVE ID that affects a product developed by Ragic — matched by CVE ID, not by vendor name.