Vermeg's vulnerability footprint centers on Agile Reporter, a business intelligence and reporting platform, with the observed exposure rooted in web application input-handling issues including cross-site scripting and improper XML entity reference handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vermeg over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34832MEDIUM An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component. | Oct 27, 2023 | 6.5 | 20 | NO | NO |
CVE-2022-34833MEDIUM An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component. | Oct 27, 2023 | 5.4 | 17 | NO | NO |
CVE-2022-34834MEDIUM An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment action to the Activity log. | Oct 27, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vermeg.
Media articles that mention a CVE ID that affects a product developed by Vermeg — matched by CVE ID, not by vendor name.