Sage develops a focused line of enterprise resource planning and financial management software serving mid-market businesses, including products such as Sage 300, X3, and Sage FRP 1000 that handle critical accounting and operational workflows. Its vulnerability footprint, while concentrated in a relatively narrow product portfolio, skews toward serious outcomes, with a notable share reaching critical severity and a pronounced tendency toward public exploit availability. The recurring weakness classes—cross-site scripting, hard-coded credentials, and incorrect authorization—reflect the web-facing and access-control demands inherent to business-critical financial software, and together they create meaningful exposure pathways for both remote attackers and insider threats. Defenders should treat Sage software updates as urgent, particularly for internet-reachable instances and those handling sensitive financial data; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sage over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7388CRITICAL Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential vali | Jul 22, 2021 | 9.8 | 78 | NO | YES |
CVE-2020-7387MEDIUM Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. No | Jul 22, 2021 | 5.3 | 50 | NO | YES |
CVE-2022-34324HIGH Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer | Jan 1, 2023 | 8.8 | 33 | NO | NO |
CVE-2003-1242MEDIUM Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message. | Dec 31, 2003 | 5.0 | 30 | NO | YES |
CVE-2022-41400CRITICAL Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data direc | Apr 28, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-41397CRITICAL The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets store | Apr 28, 2023 | 9.8 | 28 | NO | NO |
CVE-2022-34322CRITICAL Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the context of users' browsers. The attacker need | Jan 1, 2023 | 9.0 | 28 | NO | NO |
CVE-2023-2809CRITICAL Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the | Oct 4, 2023 | 9.8 | 27 | NO | NO |
CVE-2003-1243MEDIUM Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter. | Dec 31, 2003 | 4.3 | 27 | NO | YES |
CVE-2022-38583HIGH On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstat | Apr 28, 2023 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sage.
Media articles that mention a CVE ID that affects a product developed by Sage — matched by CVE ID, not by vendor name.