Ysoft develops print and document management software centered on its SafeQ platform and server components, which are typically deployed in office and enterprise environments to manage print queues and device access. The durable signal in its vulnerability profile is a concentration of authentication and information-handling weaknesses—capture-replay vulnerabilities, cleartext transmission of credentials, cross-site scripting, and permission-assignment flaws—that reflect the web-facing and multi-user nature of centralized print-management infrastructure. Defenders should prioritize access controls and network segmentation for SafeQ deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ysoft over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15498HIGH YSoft SafeQ Server 6 allows a replay attack. | Mar 21, 2019 | 8.1 | 26 | NO | NO |
CVE-2022-23862HIGH A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to JMX MLet attacks. Because the service did | Oct 22, 2024 | 7.8 | 24 | NO | NO |
CVE-2022-38176HIGH An issue was discovered in YSoft SAFEQ 6 before 6.0.72. Incorrect privileges were configured as part of the installer package for the Client V3 services, allowing for local user pr | Sep 6, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-31859HIGH Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by overwriting the executable file via an alternative data stre | Jul 14, 2021 | 7.8 | 24 | NO | NO |
CVE-2022-23861MEDIUM Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious | Oct 22, 2024 | 5.4 | 20 | NO | NO |
CVE-2023-35833MEDIUM An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password | Jul 13, 2023 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ysoft.
Media articles that mention a CVE ID that affects a product developed by Ysoft — matched by CVE ID, not by vendor name.