Talentsoft operates a narrowly focused portfolio centered on web-based human capital management and talent management applications deployed in enterprise environments. The vendor's disclosures cluster around its web-facing server and application components, where the recurring weakness classifications reflect broad input-handling and integration concerns typical of web-delivered business software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Talentsoft over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0449HIGH Buffer overflow in webpsvc.exe for Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long argument to webplus.exe program, which triggers the | Jul 26, 2002 | 10.0 | 34 | NO | NO |
CVE-2002-0753HIGH Buffer overflow in Talentsoft Web+ 5.0 allows remote attackers to execute arbitrary code via an HTTP request with a long cookie. | Aug 12, 2002 | 10.0 | 32 | NO | NO |
CVE-2000-0282MEDIUM TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program. | Apr 12, 2000 | 5.0 | 27 | NO | YES |
CVE-2002-0450HIGH Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplu | Jul 26, 2002 | 10.0 | 26 | NO | NO |
CVE-2006-1682MEDIUM Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname param | Apr 11, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-1897MEDIUM Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') o | Apr 20, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Talentsoft.
Media articles that mention a CVE ID that affects a product developed by Talentsoft — matched by CVE ID, not by vendor name.