Sync develops a focused portfolio of XML-centric authoring, editing, and content publishing tools, including Oxygen XML Author, Developer, and Editor variants alongside content fusion and publishing engine products. The durable signal across its disclosures centers on path-traversal, cross-site scripting, and XML external entity injection weaknesses, which are characteristic of document-processing and web-facing content platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sync over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20191HIGH Oxygen XML Editor 21.1.1 allows XXE to read any file. | Mar 16, 2020 | 7.5 | 24 | NO | NO |
CVE-2021-46827MEDIUM An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online document | Jul 13, 2022 | 6.1 | 21 | NO | NO |
CVE-2023-26559MEDIUM A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read fil | Apr 14, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sync.
Media articles that mention a CVE ID that affects a product developed by Sync — matched by CVE ID, not by vendor name.