Xigla develops a focused suite of web-based content-management and support applications, including image galleries, news managers, poll systems, and live-chat platforms, that serve small-to-medium business and publishing deployments. The vendor's vulnerability profile concentrates on application-layer input-handling and authentication weaknesses—SQL injection, cross-site scripting, improper authentication, and input-validation flaws—that are characteristic of legacy web applications built without modern framework protections. Notably, vulnerabilities affecting this vendor frequently acquire public exploit tooling, reflecting both the relative age of the codebase and the accessibility of web-application attack patterns. Defenders deploying these products should prioritize network segmentation and access controls, monitor for exploitation attempts, and maintain an aggressive patching posture; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xigla over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6864HIGH Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6863HIGH Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6862HIGH Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6861HIGH Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6860HIGH Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6859HIGH Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6858HIGH Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6857HIGH Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6856HIGH Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6855HIGH Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie. | Jul 14, 2009 | 7.5 | 29 | NO | YES |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xigla.
Media articles that mention a CVE ID that affects a product developed by Xigla — matched by CVE ID, not by vendor name.