pleasanter CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

pleasanter vulnerability overview

Aggregates CVE and security vulnerability intelligence across all pleasanter-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting, vendor risk open redirect, and vendor risk path handling; exposure may include vendor impact session compromise in vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-21584 Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and perform a specific operation, an arbitrary script may be executed on the web browser of the user. [email protected] 6.1 0.73% 2024-03-12 2025-03-13
CVE-2023-46688 Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. [email protected] 6.1 0.63% 2023-12-06 2024-11-21
CVE-2023-45210 Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access. [email protected] 4.3 0.25% 2023-12-06 2025-05-28
CVE-2023-34439 Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser. [email protected] 5.4 0.49% 2023-12-06 2024-11-21
CVE-2023-32608 Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to alter an arbitrary file on the server. [email protected] 6.5 0.43% 2023-06-30 2024-11-21
CVE-2023-32607 Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script. [email protected] 5.4 0.37% 2023-06-30 2024-11-21
CVE-2023-30758 Cross-site scripting vulnerability in Pleasanter 1.3.38.1 and earlier allows a remote authenticated attacker to inject an arbitrary script. [email protected] 5.4 0.40% 2023-06-01 2025-01-09
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence