Xbtitfm is a narrowly scoped vendor with a focused product footprint centered on a file-transfer and titling management application. Its observed vulnerabilities cluster around input-handling and file-management flaws, including path traversal, SQL injection, and unrestricted file upload issues that are typical of web-facing applications handling user-supplied data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xbtitfm over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-58309CRITICAL xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malicious SQL code through the msgid | Dec 11, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-58312HIGH xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit | Dec 11, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-58313HIGH xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through th | Dec 11, 2025 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xbtitfm.
Media articles that mention a CVE ID that affects a product developed by Xbtitfm — matched by CVE ID, not by vendor name.