Vertikalsystems develops hospital management backend services, a healthcare-focused application whose vulnerability profile centers on information-disclosure weaknesses including exposure of sensitive system data to unauthorized control spheres and error messages containing sensitive information. These disclosure patterns are characteristic of healthcare application development where patient and operational data protection is critical; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vertikalsystems over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54459HIGH Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live | Oct 29, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-61959MEDIUM Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET versi | Oct 29, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vertikalsystems.
Media articles that mention a CVE ID that affects a product developed by Vertikalsystems — matched by CVE ID, not by vendor name.