Skip to content
Noroxi

GestSup records

8 published records for vendor gestsup.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

8 records
  • Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote).

    CriticalCVSS 9.8No exploitEPSS 1%

    gestsup · gestsupApr 26, 2021

  • GestSup <= 3.2.60 CSRF Allows Privileged Actions

    HighCVSS 8.9No exploitEPSS 0%

    gestsup · gestsupJan 9, 2026

  • GestSup < 3.2.60 Multiple SQL Injections in Asset List

    HighCVSS 7.5No exploitEPSS 0%

    gestsup · gestsupJan 9, 2026

  • GestSup < 3.2.60 SQL Injection in Search Bar

    HighCVSS 7.7No exploitEPSS 0%

    gestsup · gestsupJan 9, 2026

  • GestSup < 3.2.60 SQL Injection in Ticket Creation

    HighCVSS 7.7No exploitEPSS 0%

    gestsup · gestsupJan 9, 2026

  • A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa

    MediumCVSS 5.4No exploitEPSS 0%

    gestsup · gestsupFeb 12, 2024

  • GestSup < 3.2.60 Stored XSS in API Error Logs

    MediumCVSS 5.1No exploitEPSS 0%

    gestsup · gestsupJan 9, 2026

  • A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.

    MediumCVSS 4.3No exploitEPSS 0%

    gestsup · gestsupFeb 12, 2024