sefrengo CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

sefrengo vulnerability overview

Aggregates CVE and security vulnerability intelligence across all sefrengo-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk sql injection and vendor risk cross-site scripting; exposure may include vendor impact data exposure and vendor impact session compromise in vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2015-5052 SQL injection vulnerability in Sefrengo before 1.6.5 beta2. [email protected] 9.8 0.31% 2017-09-07 2026-05-13
CVE-2015-1428 Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL commands via the sefrengo cookie in a login to backend/main.php or (2) remote authenticated users to execute arbitrary SQL commands via the value_id parameter in a save_value action to backend/main.php. [email protected] 7.5 1.41% 2015-02-03 2026-05-06
CVE-2015-0919 Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php. [email protected] 7.5 1.00% 2015-01-08 2026-05-06
CVE-2015-0918 Cross-site scripting (XSS) vulnerability in the administrative backend in Sefrengo before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter to backend/main.php. [email protected] 4.3 0.46% 2015-01-08 2026-05-06
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence