Xpand It maintains a narrow portfolio of enterprise software products focused on Atlassian ecosystem integration and testing tools, including Write Back Manager and Xray Test Management. Despite modest disclosure volume, these products serve specialized roles in development and quality-assurance workflows where they are embedded across organizations using Jira and related platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xpand It over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27168CRITICAL An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file. | Jan 19, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-27172CRITICAL Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack. | Dec 20, 2023 | 9.1 | 25 | NO | NO |
CVE-2023-27170HIGH Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter. | Oct 26, 2023 | 7.5 | 19 | NO | NO |
CVE-2019-19679MEDIUM In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create P | Dec 9, 2019 | 5.4 | 18 | NO | NO |
CVE-2019-19678MEDIUM In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry point via the Generic Test Definition field of a | Dec 9, 2019 | 5.4 | 18 | NO | NO |
CVE-2023-27169MEDIUM Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for l | Sep 12, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xpand It.
Media articles that mention a CVE ID that affects a product developed by Xpand It — matched by CVE ID, not by vendor name.