Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sage

First CVE: Dec 31, 2003Active for: 23 yearsTotal CVEs: 28
42.2
VTI Score
High

Sage develops a focused line of enterprise resource planning and financial management software serving mid-market businesses, including products such as Sage 300, X3, and Sage FRP 1000 that handle critical accounting and operational workflows. Its vulnerability footprint, while concentrated in a relatively narrow product portfolio, skews toward serious outcomes, with a notable share reaching critical severity and a pronounced tendency toward public exploit availability. The recurring weakness classes—cross-site scripting, hard-coded credentials, and incorrect authorization—reflect the web-facing and access-control demands inherent to business-critical financial software, and together they create meaningful exposure pathways for both remote attackers and insider threats. Defenders should treat Sage software updates as urgent, particularly for internet-reachable instances and those handling sensitive financial data; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sage over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Oct 30, 2024
632 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-7388CRITICAL
Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential vali
Jul 22, 20219.878NOYES
CVE-2020-7387MEDIUM
Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. No
Jul 22, 20215.350NOYES
CVE-2022-34324HIGH
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer
Jan 1, 20238.833NONO
CVE-2003-1242MEDIUM
Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.
Dec 31, 20035.030NOYES
CVE-2022-41400CRITICAL
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data direc
Apr 28, 20239.829NONO
CVE-2022-41397CRITICAL
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets store
Apr 28, 20239.828NONO
CVE-2022-34322CRITICAL
Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the context of users' browsers. The attacker need
Jan 1, 20239.028NONO
CVE-2023-2809CRITICAL
Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the
Oct 4, 20239.827NONO
CVE-2003-1243MEDIUM
Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter.
Dec 31, 20034.327NOYES
CVE-2022-38583HIGH
On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstat
Apr 28, 20237.826NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
43%
39%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (7.1%)
Network21 (75.0%)
Unknown5 (17.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (82.1%)
High0 (0.0%)
Unknown5 (17.9%)
User Interaction
None17 (60.7%)
Unknown5 (17.9%)
Required6 (21.4%)
Privileges Required
Low11 (39.3%)
High3 (10.7%)
None9 (32.1%)
Unknown5 (17.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
7.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
10.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sage.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sage — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sage's Products

View all 4 CNAs →

Top CWEs