Skinsoft's vulnerability footprint concentrates in web-based museum applications, with observed weaknesses centered on file-upload handling and input-sanitization deficiencies that are typical of interactive web platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skinsoft over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25802CRITICAL SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content. | Feb 22, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-25801MEDIUM SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the content) of a file. | Feb 22, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skinsoft.
Media articles that mention a CVE ID that affects a product developed by Skinsoft — matched by CVE ID, not by vendor name.