Aggregates CVE and security vulnerability intelligence across all yordam-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk cross-site scripting and vendor risk path handling, with potential vendor impact session compromise and vendor impact file overwrite across vendor surface production workloads use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-1301 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Informatics Library Automation System allows Reflected XSS.This issue affects Library Automation System: before 21.6. | [email protected] | 6.1 | 0.17% | 2025-05-02 | 2025-09-12 |
| CVE-2023-4676 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yordam MedasPro allows Reflected XSS. This issue affects MedasPro: before 28. | [email protected] | 6.1 | 0.18% | 2023-09-14 | 2026-05-21 |
| CVE-2021-45479 | Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS. This issue affects Library Automation System: before 19.2. | [email protected] | 5.4 | 0.18% | 2023-03-02 | 2026-05-18 |
| CVE-2021-45478 | Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2. | [email protected] | 6.5 | 0.34% | 2023-03-02 | 2026-05-18 |
| CVE-2021-45477 | Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2. | [email protected] | 6.5 | 0.34% | 2023-03-02 | 2026-05-18 |
| CVE-2021-45476 | Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnerability. | [email protected] | 4.7 | 0.34% | 2022-10-27 | 2026-05-18 |
| CVE-2021-45475 | Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosure vulnerability. | [email protected] | 5.3 | 0.31% | 2022-10-27 | 2026-05-18 |
| CVE-2022-2266 | University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated Reflected XSS vulnerability. This has been fixed in the version 19.2 | [email protected] | 6.1 | 0.34% | 2022-09-22 | 2026-05-20 |