BigProf records
22 published records for vendor bigprof.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-35674No exploit | BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoinbigprof · online invoicing system · CWE-89 | Critical9.8 | — | 1.1% | Sep 28, 2022 |
35Monitor | CVE-2020-35675No exploit | BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups.bigprof · online invoicing system · CWE-352 | High8.8 | — | 0.5% | Sep 28, 2022 |
24Monitor | CVE-2020-35676No exploit | BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration funcbigprof · online invoicing system · CWE-79 | Medium6.1 | — | 0.8% | Dec 24, 2020 |
24Monitor | CVE-2020-6583No exploit | BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking.bigprof · online invoicing system · CWE-79 | Medium6.1 | — | 0.7% | Jan 8, 2020 |
21Monitor | CVE-2021-21260No exploit | XSS in description fieldbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.6% | Jan 22, 2021 |
21Monitor | CVE-2018-18587No exploit | BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.bigprof · appgini · CWE-327 | Medium5.3 | — | 0.5% | Oct 23, 2018 |
21Monitor | CVE-2023-6425No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6435No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6422No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6423No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6424No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online clinic management system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6433No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6434No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6426No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6427No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6428No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6429No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6430No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6431No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
21Monitor | CVE-2023-6432No exploit | Cross-site Scripting vulnerability in BigProf productsbigprof · online invoicing system · CWE-79 | Medium5.4 | — | 0.4% | Nov 30, 2023 |
19Monitor | CVE-2020-35677No exploit | BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEdibigprof · online invoicing system · CWE-79 | Medium4.8 | — | 0.3% | Dec 24, 2020 |
17Monitor | CVE-2021-27839No exploit | A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions subigprof · online invoicing system · CWE-1236 | Medium4.4 | — | 0.7% | Mar 3, 2021 |
- CVE-2020-3567439Monitor
BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoin
CriticalCVSS 9.8No exploitEPSS 1%bigprof · online invoicing systemSep 28, 2022
- CVE-2020-3567535Monitor
BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups.
HighCVSS 8.8No exploitEPSS 0%bigprof · online invoicing systemSep 28, 2022
- CVE-2020-3567624Monitor
BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration func
MediumCVSS 6.1No exploitEPSS 1%bigprof · online invoicing systemDec 24, 2020
- CVE-2020-658324Monitor
BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking.
MediumCVSS 6.1No exploitEPSS 1%bigprof · online invoicing systemJan 8, 2020
- CVE-2021-2126021Monitor
XSS in description field
MediumCVSS 5.4No exploitEPSS 1%bigprof · online invoicing systemJan 22, 2021
- CVE-2018-1858721Monitor
BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.
MediumCVSS 5.3No exploitEPSS 1%bigprof · appginiOct 23, 2018
- CVE-2023-642521Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online clinic management systemNov 30, 2023
- CVE-2023-643521Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-642221Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online clinic management systemNov 30, 2023
- CVE-2023-642321Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online clinic management systemNov 30, 2023
- CVE-2023-642421Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online clinic management systemNov 30, 2023
- CVE-2023-643321Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-643421Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-642621Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-642721Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-642821Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-642921Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-643021Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-643121Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2023-643221Monitor
Cross-site Scripting vulnerability in BigProf products
MediumCVSS 5.4No exploitEPSS 0%bigprof · online invoicing systemNov 30, 2023
- CVE-2020-3567719Monitor
BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEdi
MediumCVSS 4.8No exploitEPSS 0%bigprof · online invoicing systemDec 24, 2020
- CVE-2021-2783917Monitor
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform malicious actions su
MediumCVSS 4.4No exploitEPSS 1%bigprof · online invoicing systemMar 3, 2021