Realtyworkstation's vulnerability profile centers on its real-estate management application, with observed weaknesses spanning authentication bypass via alternate paths, SQL injection, and missing authentication controls for critical functions. These are characteristic input-validation and access-control gaps in web-facing business applications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Realtyworkstation over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50489CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Re | Oct 28, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-1691MEDIUM The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, lea | Jun 8, 2022 | 4.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Realtyworkstation.
Media articles that mention a CVE ID that affects a product developed by Realtyworkstation — matched by CVE ID, not by vendor name.