Sparkdevnetwork

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    4
    Critical Level Threats
    0
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-36748

    RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

    Last Modified: Jun 05, 2026
    Published: Jun 03, 2026

    CVE-2019-18642

    Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any user to change account details of any other user. This vulnerability could be used to change the email address of another account, even the administrator account. Upon changing another account's email address, performing a password reset to the new email address could allow an attacker to take over any account.

    Last Modified: Nov 21, 2024
    Published: Jan 07, 2021

    CVE-2019-18643

    Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow an attacker to upload ASPX code and gain remote code execution on the application. The application typically runs as LocalSystem as mandated in the installation guide. Patched in versions 8.10 and 9.4.

    Last Modified: Nov 21, 2024
    Published: Jan 07, 2021

    CVE-2019-18641

    Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.

    Last Modified: Nov 21, 2024
    Published: Mar 20, 2020
    Items Per Page
    Sparkdevnetwork Vulnerabilities & Security CVEs | CVE-DB