Scytl develops election and voting infrastructure software, with its Secure Vote platform presenting a critical-path system where authentication and command-execution integrity are essential to operational security. The recurring vulnerability signal centers on authentication bypasses through spoofing and hard-coded credentials, as well as OS command injection and missing authentication controls for sensitive functions—weakness classes that reflect risks inherent to systems handling sensitive procedural logic and external input in a high-stakes voting context. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scytl over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25022CRITICAL An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the ap | Feb 27, 2021 | 9.8 | 29 | NO | NO |
CVE-2019-25021HIGH An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access the OrientDB by providing admin as the admin password. A diffe | Feb 27, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-25020HIGH An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can retrieve the administrative configuration by sending a POST | Feb 27, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-25023MEDIUM An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipulated client-side) is used for the internal application logs, | Feb 27, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scytl.
Media articles that mention a CVE ID that affects a product developed by Scytl — matched by CVE ID, not by vendor name.