Products: 1
Vulnerabilities: 4
Known Exploited: 0
1
Critical Level Threats
0
High Level Threats
3
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2024-57189
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.
Last Modified: Jun 24, 2025
Published: Jun 10, 2025
CVE-2024-57186
In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.
Last Modified: Jun 23, 2025
Published: Jun 10, 2025
CVE-2024-57190
Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.
Last Modified: Jun 24, 2025
Published: Jun 10, 2025
CVE-2021-32853
Erxes vulnerable to Cross-site Scripting
Last Modified: Mar 10, 2025
Published: Feb 20, 2023
Items Per Page
