Sytel maintains SoftDial, a contact-center platform where observed vulnerabilities cluster around web application security and file-handling issues, including path traversal, cross-site scripting, and unrestricted file uploads. This represents a narrowly scoped vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sytel over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2494CRITICAL Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ | Mar 18, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-2493HIGH Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘/softdial/scheduler/load.php’ e | Mar 18, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-2495MEDIUM Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to upload XML files to the server with JavaScript code injected via | Mar 18, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sytel.
Media articles that mention a CVE ID that affects a product developed by Sytel — matched by CVE ID, not by vendor name.