Webvendome Project maintains a narrowly scoped web application product where the durable vulnerability signal centers on application-layer input-handling issues, specifically path-traversal and SQL-injection flaws. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webvendome Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36787CRITICAL
webvendome - webvendome SQL Injection.
SQL Injection in the Parameter " DocNumber"
Request :
Get Request :
/webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.
| Nov 17, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-39178MEDIUM
Webvendome - webvendome Internal Server IP Disclosure.
Send GET Request to the request which is shown in the picture.
Internal Server IP and Full path disclosure.
| Nov 17, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webvendome Project.
Media articles that mention a CVE ID that affects a product developed by Webvendome Project — matched by CVE ID, not by vendor name.