Spacetag operates a narrowly scoped portfolio centered on the Lacoodast application, presenting a focused web application surface. The recurring vulnerability pattern reflects typical application-layer weaknesses, including cross-site request forgery, improper authentication, code injection, and cross-site scripting, which recur across the vendor's disclosures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spacetag over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3738CRITICAL Session fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectors. | Aug 27, 2008 | 9.1 | 28 | NO | NO |
CVE-2008-3737HIGH Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scr | Aug 27, 2008 | 10.0 | 25 | NO | NO |
CVE-2008-3736MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allow remote attack | Aug 27, 2008 | 6.0 | 16 | NO | NO |
CVE-2008-3739MEDIUM Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arb | Aug 27, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spacetag.
Media articles that mention a CVE ID that affects a product developed by Spacetag — matched by CVE ID, not by vendor name.