Smartsoft's vulnerability footprint centers on web-based productivity and business-process management products, specifically SmartBPM.net and related components, with exposure rooted in authentication and input-handling weaknesses. The recurring weakness classes—hard-coded credentials, cross-site request forgery, and path-traversal variants—reflect common risks in web applications where credential management and request validation require careful implementation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartsoft over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37286CRITICAL SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to e | Jul 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-37287CRITICAL SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privil | Jul 10, 2023 | 9.1 | 26 | NO | NO |
CVE-2023-37288HIGH SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrar | Jul 10, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-1912HIGH The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the | Jul 18, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartsoft.
Media articles that mention a CVE ID that affects a product developed by Smartsoft — matched by CVE ID, not by vendor name.