Stimulsoft

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 9
    Known Exploited: 0
    4
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-24398

    Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

    Last Modified: May 15, 2025
    Published: Feb 06, 2024

    CVE-2024-24397

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.

    Last Modified: May 15, 2025
    Published: Feb 05, 2024

    CVE-2024-24396

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.

    Last Modified: Nov 21, 2024
    Published: Feb 05, 2024

    CVE-2023-25260

    Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

    Last Modified: Feb 19, 2025
    Published: Mar 28, 2023

    CVE-2023-25262

    Stimulsoft GmbH Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Server Side Request Forgery (SSRF). TThe Reporting Designer (Web) offers the possibility to embed sources from external locations. If the user chooses an external location, the request to that resource is performed by the server rather than the client. Therefore, the server causes outbound traffic and potentially imports data. An attacker may also leverage this behaviour to exfiltrate data of machines on the internal network of the server hosting the Stimulsoft Reporting Designer (Web).

    Last Modified: Feb 19, 2025
    Published: Mar 28, 2023
    Items Per Page
    Stimulsoft Vulnerabilities & Security CVEs | CVE-DB