Sagedpw's vulnerability profile concentrates in its Sage DPW product, a modestly represented but prominent web-based application that faces recurrent exposure through client-side and access-control weaknesses. The durable signal centers on input-handling issues such as cross-site scripting, combined with authorization and information-disclosure vulnerabilities that reflect the product's web-facing role and the authentication and data-protection demands of its user-facing interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sagedpw over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-51532HIGH Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that | Aug 6, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-67805HIGH A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Database Monitor feature, exposing sensitive information such a | Apr 1, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-51531MEDIUM A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser via i | Aug 6, 2025 | 6.1 | 22 | NO | NO |
CVE-2024-56883HIGH Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage us | Feb 18, 2025 | 8.1 | 22 | NO | NO |
CVE-2020-26584MEDIUM An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog is vulnerable to Reflected XSS. If the attacker can lure a | Oct 16, 2020 | 6.1 | 21 | NO | NO |
CVE-2025-51533MEDIUM An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request. | Aug 7, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-67806MEDIUM The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. O | Apr 1, 2026 | 5.3 | 19 | NO | NO |
CVE-2025-67807MEDIUM The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. O | Apr 1, 2026 | 4.7 | 17 | NO | NO |
CVE-2024-56882MEDIUM Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the Kursti | Feb 18, 2025 | 5.4 | 17 | NO | NO |
CVE-2020-26583MEDIUM An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses claiming functionality. However, | Oct 16, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sagedpw.
Media articles that mention a CVE ID that affects a product developed by Sagedpw — matched by CVE ID, not by vendor name.