Reportico is a reporting and analytics platform with a focused product footprint centered on its core Reportico application and PHP-based report designer, serving business intelligence and data visualization use cases. The vulnerability profile concentrates on access-control and input-handling weaknesses, particularly improper authentication mechanisms, path-traversal conditions in file operations, and cross-site scripting in report output generation. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reportico over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48865MEDIUM An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL. | Apr 11, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-46925MEDIUM Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS). | Nov 2, 2023 | 4.8 | 16 | NO | NO |
CVE-2014-3777MEDIUM Directory traversal vulnerability in Reportico PHP Report Designer before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the xmlin parameter. | Jul 16, 2014 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reportico.
Media articles that mention a CVE ID that affects a product developed by Reportico — matched by CVE ID, not by vendor name.