Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gestsup HIGH 8.1
CVE-2026-22196

GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket…

Fix: after 3.2.56
Fix from $1,950 2026-01-09
Gestsup HIGH 8.1
CVE-2026-22197

GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to …

Fix: after 3.2.56
Fix from $1,950 2026-01-09
Gestsup MEDIUM 6.1
CVE-2026-22198

GestSup versions prior to 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API error logging functionality.…

Fix: after 3.2.56
Fix from $1,600 2026-01-09
Gestsup HIGH 8.8
CVE-2026-22194

GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authe…

Fix: after 3.2.56
Fix from $1,950 2026-01-09
Gestsup HIGH 8.1
CVE-2026-22195

GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated …

Fix: after 3.2.56
Fix from $1,950 2026-01-09
Gestsup MEDIUM 5.4
CVE-2023-52059

A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injecte…

Fix: 3.2.46+
Fix from $1,600 2024-02-13
Gestsup CRITICAL 9.8
CVE-2021-31646

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php…

Fix: 3.2.10+
Fix from $2,300 2021-04-26