spinetix CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

spinetix vulnerability overview

Aggregates CVE and security vulnerability intelligence across all spinetix-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk path handling, vendor risk csrf, and vendor risk ssrf, with potential vendor impact file overwrite across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-36888 SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error responses. [email protected] 6.9 0.34% 2025-12-10 2026-06-16
CVE-2020-36887 SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information. [email protected] 8.7 0.35% 2025-12-10 2026-06-16
CVE-2020-36886 SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges when a logged-in user visits the page. [email protected] 6.9 0.22% 2025-12-10 2026-06-16
CVE-2020-36883 SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attackers can exploit path traversal techniques in index.php to write backup files to arbitrary locations and delete files by manipulating backup and file delete requests. [email protected] 8.8 0.76% 2025-12-10 2026-06-16
CVE-2020-15809 spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd. [email protected] 6.5 0.94% 2021-03-24 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence