Dradisframework

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-50458

    In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

    Last Modified: Nov 07, 2025
    Published: Jul 10, 2025

    CVE-2023-50786

    Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.

    Last Modified: Nov 07, 2025
    Published: Jul 05, 2025

    CVE-2023-31223

    Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.

    Last Modified: May 30, 2025
    Published: Apr 25, 2023

    CVE-2022-30028

    Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2022

    CVE-2019-19946

    The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.

    Last Modified: Nov 21, 2024
    Published: Mar 16, 2020
    Items Per Page
    Dradisframework Vulnerabilities & Security CVEs | CVE-DB