Skip to content
Noroxi

dradisframework records

6 published records for vendor dradisframework.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
16.7%
Median publish → KEV
No record has entered KEV

All records

6 records
  • The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.

    MediumCVSS 6.5No exploitEPSS 1%

    dradisframework · dradisMar 16, 2020

  • Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.

    MediumCVSS 5.9No exploitEPSS 1%

    dradisframework · dradisJun 24, 2022

  • CVE-2019-5925
    21Monitor

    Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3

    MediumCVSS 5.4No exploitEPSS 1%

    dradisframework · dradisMar 12, 2019

  • Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.

    MediumCVSS 5.4No exploitEPSS 1%

    dradisframework · dradisApr 25, 2023

  • Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images.

    MediumCVSS 4.3No exploitEPSS 0%

    dradisframework · dradisJul 5, 2025

  • In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

    MediumCVSS 4.3No exploitEPSS 0%

    dradisframework · dradisJul 10, 2025