dradisframework records
6 published records for vendor dradisframework.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1230 Exposure of Sensitive Information Through Metadata1
- CWE-294 Authentication Bypass by Capture-replay1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2019-19946No exploit | The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.dradisframework · dradis · CWE-639 | Medium6.5 | — | 1.2% | Mar 16, 2020 |
23Monitor | CVE-2022-30028No exploit | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.dradisframework · dradis · CWE-362 | Medium5.9 | — | 0.5% | Jun 24, 2022 |
21Monitor | CVE-2019-5925No exploit | Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3dradisframework · dradis · CWE-79 | Medium5.4 | — | 0.8% | Mar 12, 2019 |
21Monitor | CVE-2023-31223No exploit | Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.dradisframework · dradis · CWE-79 | Medium5.4 | — | 0.5% | Apr 25, 2023 |
17Monitor | CVE-2023-50786No exploit | Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images.dradisframework · dradis · CWE-294 | Medium4.3 | — | 0.3% | Jul 5, 2025 |
17Monitor | CVE-2023-50458No exploit | In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.dradisframework · dradis · CWE-1230 | Medium4.3 | — | 0.2% | Jul 10, 2025 |
- CVE-2019-1994626Monitor
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
MediumCVSS 6.5No exploitEPSS 1%dradisframework · dradisMar 16, 2020
- CVE-2022-3002823Monitor
Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.
MediumCVSS 5.9No exploitEPSS 1%dradisframework · dradisJun 24, 2022
- CVE-2019-592521Monitor
Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3
MediumCVSS 5.4No exploitEPSS 1%dradisframework · dradisMar 12, 2019
- CVE-2023-3122321Monitor
Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
MediumCVSS 5.4No exploitEPSS 1%dradisframework · dradisApr 25, 2023
- CVE-2023-5078617Monitor
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images.
MediumCVSS 4.3No exploitEPSS 0%dradisframework · dradisJul 5, 2025
- CVE-2023-5045817Monitor
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
MediumCVSS 4.3No exploitEPSS 0%dradisframework · dradisJul 10, 2025