Savignano
Savignano's vulnerability profile is concentrated in a narrow product scope—notably its S-Notify notification system—where the recurring signal centers on web application input-handling and request-validation issues such as cross-site scripting and cross-site request forgery. These weakness classes are characteristic of web-facing applications and reflect the input-processing demands of notification and messaging systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Savignano over time
Products(1 total)
Top CVEs
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50930HIGH An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF at | Jan 9, 2024 | 7.1 | 19 | NO | NO |
CVE-2024-23737MEDIUM Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP ke | Jul 1, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-23735MEDIUM Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attack | Apr 10, 2024 | 6.1 | 16 | NO | NO |
CVE-2024-23734MEDIUM Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME | Apr 10, 2024 | 5.2 | 16 | NO | NO |
CVE-2023-50932MEDIUM An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a C | Jan 9, 2024 | 5.4 | 16 | NO | NO |
CVE-2023-50931MEDIUM An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CS | Jan 9, 2024 | 5.4 | 16 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (6 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Savignano.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Savignano — matched by CVE ID, not by vendor name.