bladex springblade CVE Vulnerabilities (9)

CVEs: 9 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting bladex springblade (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 19 of 9 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-70982 Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data. [email protected] 9.9 0.05% 2026-01-26 2026-02-12
CVE-2025-70983 Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges. [email protected] 9.9 0.01% 2026-01-23 2026-02-11
CVE-2024-8023 A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 5.3 0.08% 2024-08-21 2025-06-04
CVE-2024-33332 An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant. [email protected] 7.5 0.15% 2024-04-30 2025-06-03
CVE-2023-47458 An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework. [email protected] 9.8 0.92% 2024-01-02 2025-04-17
CVE-2023-40788 SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs [email protected] 5.3 0.07% 2023-09-19 2024-11-21
CVE-2023-40787 In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. [email protected] 9.8 1.27% 2023-08-29 2024-11-21
CVE-2022-27360 SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. [email protected] 9.8 0.59% 2022-05-05 2024-11-21
CVE-2020-16165 The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters. [email protected] 9.8 0.24% 2020-07-30 2025-06-03
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence