Sfs maintains a focused set of insurance-sector applications including WinSure and Insuree GL, with a durable vulnerability signal centered on injection and code-generation weaknesses such as SQL injection, code injection, and improper XML entity handling. These application-layer input-validation and templating issues reflect the data-processing demands typical of financial and policy-management software; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sfs over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7104CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection.
This issue affects ww.Winsure: before 4.6.2. | Sep 16, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-7098CRITICAL Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.
This issue affects ww.Winsure: before 4.6.2. | Sep 16, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-6401CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection.
This issue affects InsureE GL | Sep 16, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sfs.
Media articles that mention a CVE ID that affects a product developed by Sfs — matched by CVE ID, not by vendor name.