Skip to content
Noroxi

erxes records

4 published records for vendor erxes.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
75%
Median publish → KEV
No record has entered KEV

All records

4 records
  • Erxes vulnerable to Cross-site Scripting

    CriticalCVSS 9.6Proof of conceptEPSS 3%

    erxes · erxesFeb 20, 2023

  • Erxes <1.6.1 is vulnerable to Incorrect Access Control.

    CriticalCVSS 9.8No exploitEPSS 1%

    erxes · erxesJun 10, 2025

  • In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file

    MediumCVSS 5.4No exploitEPSS 0%

    erxes · erxesJun 10, 2025

  • In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHist

    MediumCVSS 5.4No exploitEPSS 0%

    erxes · erxesJun 10, 2025