Sapplica's vulnerability footprint centers on its Sentrifugo human-capital management platform, a web-based application where disclosures cluster around input-handling and access-control weaknesses. Its vulnerabilities skew strongly toward critical-severity outcomes and recur through SQL injection, cross-site scripting, unrestricted file upload, and cross-site request forgery—characteristic flaws of web applications where inadequate input sanitization and session validation create broad exploitation surfaces. Defenders should prioritize patching this vendor's releases and restrict network exposure of the platform; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sapplica over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15873CRITICAL A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter. | Aug 28, 2018 | 9.8 | 29 | NO | NO |
CVE-2024-29876CRITICAL SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a | Mar 21, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-29870CRITICAL SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/fo | Mar 21, 2024 | 9.8 | 27 | NO | NO |
CVE-2020-26803HIGH In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can | Nov 12, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-16059HIGH Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML | Sep 6, 2019 | 8.8 | 27 | NO | NO |
CVE-2024-29875CRITICAL SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. The exploitation of this vulnerability cou | Mar 21, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-29874CRITICAL SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. The exploitation of this vulnerability could a | Mar 21, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-29872CRITICAL SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploitation of this vulnerability could allow a remote u | Mar 21, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-29871CRITICAL SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. The exploitation o | Mar 21, 2024 | 9.8 | 26 | NO | NO |
CVE-2020-26804HIGH In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This " | Nov 12, 2020 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sapplica.
Media articles that mention a CVE ID that affects a product developed by Sapplica — matched by CVE ID, not by vendor name.