Viafirma produces a focused line of document-handling and messaging products, including a documents platform, composition tool, and inbox application, that rely on authorization mechanisms to protect sensitive workflows. The recurring vulnerability signal centers on authorization bypass and user-controlled key handling across these products, reflecting access-control implementation challenges in document-centric platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Viafirma over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-41078HIGH Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modi | Jan 12, 2026 | 8.1 | 27 | NO | NO |
CVE-2025-41077HIGH IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data | Jan 12, 2026 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Viafirma.
Media articles that mention a CVE ID that affects a product developed by Viafirma — matched by CVE ID, not by vendor name.