Tracefinanacial operates a focused financial services application portfolio centered on the Crestbridge product, which faces the application-layer input-handling risks typical of web-facing financial software. The durable signal here centers on SQL injection and cross-site scripting vulnerabilities, reflecting common weaknesses in web application design where user input handling and output encoding are critical controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tracefinanacial over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24671HIGH Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03. | Jun 10, 2021 | 8.8 | 26 | NO | NO |
CVE-2020-24667HIGH Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03. | Jun 10, 2021 | 8.8 | 26 | NO | NO |
CVE-2020-24663MEDIUM Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03. | Jun 10, 2021 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tracefinanacial.
Media articles that mention a CVE ID that affects a product developed by Tracefinanacial — matched by CVE ID, not by vendor name.