MagnusSolution records
4 published records for vendor magnussolution.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 25%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-269 Improper Privilege Management1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
67This week | CVE-2023-30258Weaponized | Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthentimagnussolution · magnusbilling · CWE-78 | Critical9.8 | — | 94.3% | Jun 23, 2023 |
32Monitor | CVE-2025-52289Proof of concept | A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafmagnussolution · magnusbilling · CWE-269 | High8.0 | — | 0.4% | Jul 31, 2025 |
24Monitor | CVE-2025-2609Proof of concept | MagnusBilling Stored Cross-Site Scripting in Login Logsmagnussolution · magnusbilling · CWE-79 | Medium6.1 | — | 1.1% | Mar 21, 2025 |
21Monitor | CVE-2025-2610Proof of concept | MagnusBilling Stored Cross-Site Scripting in Alarm Modulemagnussolution · magnusbilling · CWE-79 | Medium5.4 | — | 0.9% | Mar 21, 2025 |
- CVE-2023-3025867This week
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenti
CriticalCVSS 9.8WeaponizedEPSS 94%magnussolution · magnusbillingJun 23, 2023
- CVE-2025-5228932Monitor
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a craf
HighCVSS 8.0Proof of conceptEPSS 0%magnussolution · magnusbillingJul 31, 2025
- CVE-2025-260924Monitor
MagnusBilling Stored Cross-Site Scripting in Login Logs
MediumCVSS 6.1Proof of conceptEPSS 1%magnussolution · magnusbillingMar 21, 2025
- CVE-2025-261021Monitor
MagnusBilling Stored Cross-Site Scripting in Alarm Module
MediumCVSS 5.4Proof of conceptEPSS 1%magnussolution · magnusbillingMar 21, 2025