Vikisolutions maintains a focused product line centered on the Vera platform, with its vulnerability exposure clustering around web-application input handling and access-control issues including cross-site scripting, forced browsing, and unrestricted file uploads. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vikisolutions over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20484HIGH An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after | Jan 5, 2021 | 8.1 | 25 | NO | NO |
CVE-2019-15123HIGH The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Re | Jun 12, 2020 | 7.2 | 25 | NO | NO |
CVE-2019-20483MEDIUM An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the applicatio | Jan 5, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vikisolutions.
Media articles that mention a CVE ID that affects a product developed by Vikisolutions — matched by CVE ID, not by vendor name.