eramba records
11 published records for vendor eramba.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 9.1%
- Pre-auth RCE
- 0
- With a fix record
- 9.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-20 Improper Input Validation1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2023-36255Weaponized | An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path eramba · eramba · CWE-94 | High8.8 | — | 53.1% | Aug 2, 2023 |
39Monitor | CVE-2020-25105No exploit | eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).eramba · eramba · CWE-640 | Critical9.8 | — | 1.1% | Sep 3, 2020 |
26Monitor | CVE-2025-55462Proof of concept | A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in teramba · eramba · CWE-942 | Medium6.5 | — | 0.4% | Jan 13, 2026 |
24Monitor | CVE-2018-7894No exploit | Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)eramba · eramba · CWE-79 | Medium6.1 | — | 0.7% | Mar 9, 2018 |
24Monitor | CVE-2018-7741No exploit | Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.eramba · eramba · CWE-79 | Medium6.1 | — | 0.7% | Mar 7, 2018 |
24Monitor | CVE-2018-7996No exploit | Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.eramba · eramba · CWE-79 | Medium6.1 | — | 0.7% | Mar 9, 2018 |
24Monitor | CVE-2018-7997No exploit | Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file pollutederamba · eramba · CWE-79 | Medium6.1 | — | 0.6% | Mar 9, 2018 |
21Monitor | CVE-2020-25104No exploit | eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.eramba · eramba · CWE-79 | Medium5.4 | — | 0.6% | Sep 3, 2020 |
21Monitor | CVE-2022-43342No exploit | A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary weeramba · eramba · CWE-79 | Medium5.4 | — | 0.5% | Nov 14, 2022 |
21Monitor | CVE-2024-27593No exploit | A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attCWE-79 | Medium5.4 | — | 0.3% | May 15, 2024 |
17Monitor | CVE-2020-28031No exploit | eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.eramba · eramba · CWE-20 | Medium4.3 | — | 0.6% | Nov 2, 2020 |
- CVE-2023-3625551Plan
An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path
HighCVSS 8.8WeaponizedEPSS 53%eramba · erambaAug 2, 2023
- CVE-2020-2510539Monitor
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
CriticalCVSS 9.8No exploitEPSS 1%eramba · erambaSep 3, 2020
- CVE-2025-5546226Monitor
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in t
MediumCVSS 6.5Proof of conceptEPSS 0%eramba · erambaJan 13, 2026
- CVE-2018-789424Monitor
Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka the Search Parameter)
MediumCVSS 6.1No exploitEPSS 1%eramba · erambaMar 9, 2018
- CVE-2018-774124Monitor
Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.
MediumCVSS 6.1No exploitEPSS 1%eramba · erambaMar 7, 2018
- CVE-2018-799624Monitor
Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter.
MediumCVSS 6.1No exploitEPSS 1%eramba · erambaMar 9, 2018
- CVE-2018-799724Monitor
Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with a CSV file polluted
MediumCVSS 6.1No exploitEPSS 1%eramba · erambaMar 9, 2018
- CVE-2020-2510421Monitor
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object.
MediumCVSS 5.4No exploitEPSS 1%eramba · erambaSep 3, 2020
- CVE-2022-4334221Monitor
A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to execute arbitrary we
MediumCVSS 5.4No exploitEPSS 1%eramba · erambaNov 14, 2022
- CVE-2024-2759321Monitor
A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated att
MediumCVSS 5.4No exploitEPSS 0%May 15, 2024
- CVE-2020-2803117Monitor
eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.
MediumCVSS 4.3No exploitEPSS 1%eramba · erambaNov 2, 2020