Synchroweb develops a small portfolio of web-based collaboration and synchronization products, principally Kiwire and SynConnect, that handle user input and file operations in web-facing contexts. The observed vulnerability classes center on application-layer input handling and file-access control, including SQL injection, cross-site scripting, and improper link resolution, reflecting typical web-application security concerns. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Synchroweb over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2690HIGH SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff act | Mar 28, 2013 | 7.5 | 29 | NO | YES |
CVE-2025-11189HIGH The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution. | Oct 10, 2025 | 7.3 | 25 | NO | NO |
CVE-2025-11188HIGH The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database. | Oct 10, 2025 | 7.3 | 25 | NO | NO |
CVE-2025-11190MEDIUM The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website. | Oct 10, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Synchroweb.
Media articles that mention a CVE ID that affects a product developed by Synchroweb — matched by CVE ID, not by vendor name.