Shilpisoft maintains a focused portfolio of enterprise and back-office applications including Client Dashboard, CapexWeb, and Net Back Office, with vulnerabilities skewing toward serious outcomes and frequently acquiring public exploit code. The recurring exposure centers on authorization and authentication weaknesses—including user-controlled authorization keys, SQL injection, and insufficient brute-force protections—that are typical of web-based business applications where access control and input handling are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shilpisoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5031HIGH Multiple SQL injection vulnerabilities in servlet/capexweb.parentvalidatepassword in cApexWEB 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) dfuserid and | Dec 29, 2011 | 7.5 | 31 | NO | YES |
CVE-2024-47656CRITICAL This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerabi | Oct 4, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-47655HIGH This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker cou | Oct 4, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-47654HIGH This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacke | Oct 4, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-47652HIGH This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted | Oct 4, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-47657MEDIUM This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability | Oct 4, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-47653MEDIUM This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote | Oct 4, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shilpisoft.
Media articles that mention a CVE ID that affects a product developed by Shilpisoft — matched by CVE ID, not by vendor name.