Vfairs operates a web-based virtual events platform where vulnerabilities have centered on application-layer security issues, including authorization bypass through user-controlled keys, cross-site scripting, SQL injection, and unrestricted file uploads. These weakness classes are typical of web applications handling user input and access control, and reflect the authentication and data-handling surface area inherent to an event-management platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vfairs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26677HIGH Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API. | May 26, 2021 | 8.8 | 28 | NO | NO |
CVE-2020-26678HIGH vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to plac | May 26, 2021 | 8.8 | 24 | NO | NO |
CVE-2020-26680MEDIUM In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data st | May 26, 2021 | 5.4 | 20 | NO | NO |
CVE-2020-26679MEDIUM vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After | May 26, 2021 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vfairs.
Media articles that mention a CVE ID that affects a product developed by Vfairs — matched by CVE ID, not by vendor name.