Yordam maintains a narrow product portfolio focused on library automation and related systems, with a durable signal centered on web application input-handling issues such as cross-site scripting, parameter handling flaws, and sensitive information exposure. Defenders should apply standard secure-coding practices around input validation and output encoding when deploying or customizing these systems, and monitor for patches addressing the recurring web-layer weakness classes. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yordam over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45477MEDIUM Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users.
This issue affects Library Aut | Mar 2, 2023 | 6.5 | 22 | NO | NO |
CVE-2021-45476MEDIUM Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnerability. | Oct 27, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-2266MEDIUM University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated Reflected XSS vulnerability. This has been fixed in the vers | Sep 22, 2022 | 6.1 | 22 | NO | NO |
CVE-2025-1301MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Informatics Library Automation System allows Reflected XSS.
Thi | May 2, 2025 | 6.1 | 20 | NO | NO |
CVE-2021-45479MEDIUM Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS.
This issue affects Librar | Mar 2, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-4676MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yordam MedasPro allows Reflected XSS.
This issue affects MedasPro: before 28. | Sep 14, 2023 | 6.1 | 19 | NO | NO |
CVE-2021-45475HIGH Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosure vulnerability. | Oct 27, 2022 | 7.5 | 19 | NO | NO |
CVE-2021-45478MEDIUM Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users.
This issue affects Library Aut | Mar 2, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yordam.
Media articles that mention a CVE ID that affects a product developed by Yordam — matched by CVE ID, not by vendor name.