Viglet is a content management and digital experience platform centered on its Shio product, a modestly represented vendor in the vulnerability landscape. Its observed weaknesses cluster around access control, path traversal, and unrestricted file uploads—attack vectors characteristic of web-facing content platforms where input validation and authorization boundaries are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Viglet over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8344CRITICAL A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio | Jul 31, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-8343CRITICAL A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/co | Jul 31, 2025 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Viglet.
Media articles that mention a CVE ID that affects a product developed by Viglet — matched by CVE ID, not by vendor name.