Splashin maintains a focused product line centered on its core platform, with a narrow but notable vulnerability footprint. The disclosed issues cluster around improper access control and incomplete vulnerability characterization, reflecting the authentication and authorization demands of the platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Splashin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-45157MEDIUM Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users. | Jul 18, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-45156MEDIUM Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users. | Jul 18, 2025 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Splashin.
Media articles that mention a CVE ID that affects a product developed by Splashin — matched by CVE ID, not by vendor name.