4pace cadclick CVE Vulnerabilities (7)

CVEs: 7 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting 4pace cadclick (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-25905 Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the "tree" parameter. [email protected] 7.1 0.40% 2025-06-25 2025-07-07
CVE-2024-41516 A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter. [email protected] 5.4 0.39% 2024-10-04 2025-06-02
CVE-2024-41515 A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter. [email protected] 5.4 0.39% 2024-10-04 2025-06-02
CVE-2024-41514 A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter. [email protected] 5.4 0.39% 2024-10-04 2025-06-02
CVE-2024-41513 A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "searchindex" parameter. [email protected] 5.4 0.39% 2024-10-04 2025-06-02
CVE-2024-41512 A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter. [email protected] 8.8 0.65% 2024-10-04 2025-06-02
CVE-2024-41511 A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" parameter. [email protected] 3.9 0.91% 2024-10-04 2025-06-02
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence