Bitrix24

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 21
    Known Exploited: 0
    6
    Critical Level Threats
    4
    High Level Threats
    9
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-50911

    This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.

    Last Modified: Jan 16, 2026
    Published: Jan 13, 2026

    CVE-2024-34887

    Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.

    Last Modified: Nov 06, 2024
    Published: Nov 04, 2024

    CVE-2024-34882

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.

    Last Modified: Nov 06, 2024
    Published: Nov 04, 2024

    CVE-2024-34883

    Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.

    Last Modified: Nov 06, 2024
    Published: Nov 04, 2024

    CVE-2024-34885

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.

    Last Modified: Sep 04, 2025
    Published: Nov 04, 2024
    Items Per Page