Softwarepublico's vulnerability profile centers on a small portfolio of open-source Brazilian government and citizen-engagement platforms, particularly e-SIC and i3Geo, which sit on the boundary between public web exposure and data-sensitive administration. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, concentrating in classic web-application weakness classes including cross-site scripting, SQL injection, path traversal, and unrestricted file uploads that are endemic to input-handling and file-management layers. Defenders managing or monitoring these systems should treat disclosures as high-priority given their severity profile and public exploit availability; live exploitation and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Softwarepublico over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32409CRITICAL A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via | Jul 14, 2022 | 9.8 | 48 | NO | YES |
CVE-2022-34094MEDIUM Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via request_token.php. | Jul 14, 2022 | 6.1 | 32 | NO | YES |
CVE-2022-34093MEDIUM Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via access_token.php. | Jul 14, 2022 | 6.1 | 32 | NO | YES |
CVE-2017-15381CRITICAL SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script). | Oct 23, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-15379CRITICAL An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password. | Oct 23, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-15373CRITICAL E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area). | Oct 16, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-15378HIGH SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI). | Oct 23, 2017 | 8.8 | 27 | NO | NO |
CVE-2024-24350HIGH File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component. | Feb 8, 2024 | 8.8 | 22 | NO | NO |
CVE-2022-34092MEDIUM Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via svg2img.php. | Jul 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2017-15380MEDIUM XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter. | Oct 23, 2017 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Softwarepublico.
Media articles that mention a CVE ID that affects a product developed by Softwarepublico — matched by CVE ID, not by vendor name.