Rainbowfishsoftware maintains a narrowly scoped healthcare imaging product, PACSOne Server, that despite modest disclosure volume has drawn recurring focus on web-application and access-control weaknesses including cross-site scripting, SQL injection, path traversal, missing authentication for critical functions, and unrestricted file uploads—a pattern consistent with web-facing medical software. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the product's role in protecting sensitive patient data and the appeal of healthcare infrastructure as a high-value target. Current exploitation activity, severity distribution, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rainbowfishsoftware over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29165CRITICAL PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges. | Feb 3, 2021 | 9.8 | 28 | NO | NO |
CVE-2020-29164MEDIUM PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS). | Feb 3, 2021 | 6.1 | 27 | NO | YES |
CVE-2020-12870CRITICAL RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page. | Sep 30, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-29166HIGH PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure. | Feb 3, 2021 | 7.5 | 22 | NO | NO |
CVE-2020-29163HIGH PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection. | Feb 3, 2021 | 8.8 | 22 | NO | NO |
CVE-2020-12715HIGH RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control. | Sep 30, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-12869MEDIUM RainbowFish PacsOne Server 6.8.4 allows XSS. | Sep 30, 2020 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rainbowfishsoftware.
Media articles that mention a CVE ID that affects a product developed by Rainbowfishsoftware — matched by CVE ID, not by vendor name.