Topnew operates a narrowly scoped product portfolio centered on the Sidu application, a web-facing platform where its disclosed vulnerabilities reflect input-handling deficiencies, particularly cross-site scripting weaknesses in page generation. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Topnew over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7546MEDIUM An issue was discovered in SIDU 6.0. The dbs parameter of the conn.php page has a reflected Cross-site Scripting (XSS) vulnerability. | Feb 6, 2019 | 6.1 | 17 | NO | NO |
CVE-2019-7547MEDIUM An issue was discovered in SIDU 6.0. Because the database name is not strictly filtered, the attacker can insert a name containing an XSS Payload, leading to stored XSS. | Feb 6, 2019 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Topnew.
Media articles that mention a CVE ID that affects a product developed by Topnew — matched by CVE ID, not by vendor name.