Relative develops a focused product portfolio around SailPlanner and Synchrony, web-based scheduling and collaboration tools where application-layer input-handling weaknesses recur as durable signals. The observed vulnerability footprint centers on SQL injection and prototype-pollution flaws characteristic of data-driven web applications, areas where input validation and object-property integrity demand careful implementation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Relative over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7077HIGH Multiple SQL injection vulnerabilities in SailPlanner 0.3a allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | Aug 25, 2009 | 7.5 | 28 | NO | YES |
CVE-2023-45811HIGH Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitr | Oct 17, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Relative.
Media articles that mention a CVE ID that affects a product developed by Relative — matched by CVE ID, not by vendor name.