Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-46948

    A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.

    Last Modified: Apr 15, 2026
    Published: Sep 23, 2024

    CVE-2022-45287

    An access control issue in Registration.aspx of Temenos CWX 8.5.6 allows authenticated attackers to escalate privileges and perform arbitrary Administrative commands.

    Last Modified: Dec 06, 2024
    Published: Jun 21, 2023

    CVE-2023-34797

    Broken access control in the Registration page (/Registration.aspx) of Termenos CWX v8.5.6 allows attackers to access sensitive information.

    Last Modified: Dec 18, 2024
    Published: Jun 15, 2023

    CVE-2019-14251

    An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.

    Last Modified: Nov 21, 2024
    Published: Dec 09, 2019

    CVE-2019-13403

    Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leading to the viewing of user information.

    Last Modified: Nov 21, 2024
    Published: Jul 17, 2019
    Items Per Page
    Temenos Vulnerabilities & Security CVEs | CVE-DB