Vedo Suite Project maintains a specialized visualization and scientific computing software suite with a narrow product footprint but presence across research and technical domains. The vulnerability profile reflects typical application-layer and configuration weaknesses in web-facing and data-handling code: the recurring exposure centers on cleartext storage of sensitive information, improper access control, PHP remote file inclusion, cross-site scripting, and relative path traversal. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vedo Suite Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-51056HIGH An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'upl | Aug 6, 2025 | 8.2 | 29 | NO | NO |
CVE-2025-51055HIGH Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys | Aug 6, 2025 | 8.6 | 29 | NO | NO |
CVE-2025-51058MEDIUM Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers | Aug 6, 2025 | 6.5 | 25 | NO | NO |
CVE-2025-51057MEDIUM A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'read | Aug 6, 2025 | 6.5 | 25 | NO | NO |
CVE-2025-51054MEDIUM Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an e | Aug 6, 2025 | 6.5 | 25 | NO | NO |
CVE-2025-51052MEDIUM A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' fun | Aug 6, 2025 | 6.5 | 25 | NO | NO |
CVE-2025-51053MEDIUM A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject arbitrary Javascript or HTML code and potentially trigger c | Aug 6, 2025 | 6.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vedo Suite Project.
Media articles that mention a CVE ID that affects a product developed by Vedo Suite Project — matched by CVE ID, not by vendor name.