Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ecase Ecomplaint MEDIUM 5.4
CVE-2026-32869

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case informat…

Fix: 10.2.0.0+
Fix from $1,600 2026-03-19
Ecase Ecomplaint CRITICAL 9.8
CVE-2026-32865

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F…

Fix: 10.1.0.0+
Fix from $2,300 2026-03-19
Ecase Ecomplaint CRITICAL 9.8
CVE-2026-32867

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi…

Fix: 10.1.0.0+
Fix from $2,300 2026-03-19
Ecase Ecomplaint MEDIUM 5.4
CVE-2026-32866

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a user profile. An authenticated …

Fix: 10.2.0.0+
Fix from $1,600 2026-03-19
Ecase Ecomplaint MEDIUM 5.4
CVE-2026-32868

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An a…

Fix: 10.2.0.0+
Fix from $1,600 2026-03-19
Ecase Portal CRITICAL 9.8
CVE-2026-22234

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predict…

Fix: 9.0.45.0+
Fix from $2,300 2026-01-08
Ecase Ecomplaint HIGH 7.5
CVE-2026-22235

OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'ch…

Fix: 9.0.45.0+
Fix from $1,950 2026-01-08
Ecase Audit MEDIUM 5.4
CVE-2026-22232

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The Jav…

Fix: 11.14.2.0+
Fix from $1,600 2026-01-08
Ecase Audit MEDIUM 5.4
CVE-2026-22233

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed …

Fix: 11.14.2.0+
Fix from $1,600 2026-01-08
Ecase Audit HIGH 7.6
CVE-2026-22230

OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have …

Fix: 11.14.1.0+
Fix from $1,950 2026-01-08
Ecase Audit MEDIUM 5.4
CVE-2026-22231

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functionality. The JavaScript is ex…

Fix: 11.14.1.0+
Fix from $1,600 2026-01-08
Foiaxpress CRITICAL 9.8
CVE-2025-62586

OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.

Fix: 11.13.2.0+
Fix from $2,300 2025-10-16
Foiaxpress Public Access Link CRITICAL 9.8
CVE-2025-58462

OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attack…

Fix: 11.13.1.0+
Fix from $2,300 2025-09-09
Foiaxpress Public Access Link HIGH 7.5
CVE-2025-54833

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote…

Fix: 11.12.3.0+
Fix from $1,950 2025-07-31
Foiaxpress Public Access Link MEDIUM 5.3
CVE-2025-54834

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint t…

Fix: 11.12.3.0+
Fix from $1,600 2025-07-31
Foiaxpress Public Access Link CRITICAL 9.1
CVE-2024-53553

An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.

No fix yet
Fix from $2,300 2025-01-16