8.6
CVE-2025-41077 - Multiple vulnerabilities in Viafirma products
IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to…
9.3
CVE-2025-41006 - Multiple vulnerabilities in Imaster products Open configuration options
Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.
8.7
CVE-2025-41005 - Multiple vulnerabilities in Imaster products Open configuration options
Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’.
8.7
CVE-2025-41004 - Multiple vulnerabilities in Imaster products Open configuration options
Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/complaints.php’ through the ‘id’ parameter.
5.1
CVE-2025-41003 - Multiple vulnerabilities in Imaster products Open configuration options
Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/projects/hospital/admin/edit_patient.php’. By injecting a malicious script into the ‘firstname’ parameter, the JavaScript code is stored and executed every time a user accesses th…
5.1
CVE-2025-40978 - Multiple vulnerabilities in WorkDo products
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to ‘/ticket/x/conversion’, using the ‘reply_description’ parameter.
5.1
CVE-2025-40977 - Multiple vulnerabilities in WorkDo products
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation of user input by sending a POST request to ‘/store-ticket’, using the ‘subject’ and ‘description’ parameters.
5.1
CVE-2025-40976 - Multiple vulnerabilities in WorkDo products
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/ticketgo-saas/home’, using the ‘description’ parameter.
5.1
CVE-2025-40975 - Multiple vulnerabilities in WorkDo products
Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user input by sending a POST request to ‘/hrmgo/ticket/changereply’, using the ‘description’ parameter.
0.0
CVE-2026-22837 -
Not used