Sukimalab's vulnerability profile centers on a small portfolio of educational and administrative web applications, including attendance management and online lesson booking systems, where the durable signal is rooted in web-application input-handling and session-management issues. The recurring weakness classes—cross-site request forgery and cross-site scripting—are characteristic of web-facing applications where client-side request validation and output encoding are critical; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sukimalab over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5971HIGH Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vecto | Jul 5, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-5973HIGH Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified ve | Jul 5, 2019 | 8.8 | 23 | NO | NO |
CVE-2019-5972MEDIUM Cross-site scripting vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jul 5, 2019 | 6.1 | 22 | NO | NO |
CVE-2019-5970MEDIUM Cross-site scripting vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jul 5, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sukimalab.
Media articles that mention a CVE ID that affects a product developed by Sukimalab — matched by CVE ID, not by vendor name.