Squaredup develops monitoring and visualization dashboards for enterprise infrastructure platforms, particularly for System Center Operations Manager (SCOM) environments, positioning itself at the nexus of operational visibility and web-facing administration interfaces. Its vulnerability profile centers on application-layer input-handling weaknesses—cross-site scripting, cross-site request forgery, and server-side request forgery—that are characteristic of web-based management tools, with a meaningful share reaching serious severity. Defenders should prioritize patching this vendor's releases in environments where dashboards are internet-exposed or accessible to untrusted networks; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Squaredup over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40091CRITICAL An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654. | Dec 6, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-46785MEDIUM SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2). | Feb 23, 2023 | 6.1 | 22 | NO | NO |
CVE-2020-9388MEDIUM CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via | Feb 3, 2021 | 6.5 | 22 | NO | NO |
CVE-2022-46784MEDIUM SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.) | Feb 23, 2023 | 6.1 | 21 | NO | NO |
CVE-2021-40094MEDIUM A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device | Dec 7, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-40092MEDIUM A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file. | Dec 7, 2021 | 5.4 | 20 | NO | NO |
CVE-2020-9390MEDIUM SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script. | Feb 3, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-40096MEDIUM A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modifica | Dec 7, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-40093MEDIUM A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboar | Dec 7, 2021 | 5.4 | 19 | NO | NO |
CVE-2024-45180MEDIUM SquaredUp DS for SCOM 6.2.1.11104 allows XSS. | Sep 3, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Squaredup.
Media articles that mention a CVE ID that affects a product developed by Squaredup — matched by CVE ID, not by vendor name.