Visam develops a suite of web-based automation and editing products centered on its VBase platform, which occupy a notable position in the vulnerability landscape despite a narrow product portfolio. The vendor's exposure reflects characteristic flaws in web application and file-handling logic: XML external entity injection, buffer overflows, access control weaknesses, path traversal, and cross-site scripting, with vulnerabilities showing a tendency toward moderate severity outcomes. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Visam over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7004HIGH VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effe | Apr 3, 2020 | 8.8 | 26 | NO | NO |
CVE-2022-3217HIGH When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An unauthenticated remote attacker with the a | Sep 16, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-10601HIGH VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a local attacker to bypass the password-protec | Apr 3, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-10599CRITICAL VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial- | Apr 3, 2020 | 9.8 | 25 | NO | NO |
CVE-2021-42537HIGH VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the prod | Jul 27, 2022 | 7.5 | 23 | NO | NO |
CVE-2021-38417HIGH VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in th | Jul 27, 2022 | 7.5 | 23 | NO | NO |
CVE-2022-45876MEDIUM Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
| Apr 26, 2023 | 5.5 | 21 | NO | NO |
CVE-2022-46286MEDIUM Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | Mar 21, 2023 | 5.5 | 21 | NO | NO |
CVE-2022-45468MEDIUM Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | Mar 21, 2023 | 5.5 | 21 | NO | NO |
CVE-2022-45121MEDIUM Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | Mar 21, 2023 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Visam.
Media articles that mention a CVE ID that affects a product developed by Visam — matched by CVE ID, not by vendor name.