Skip to content
Noroxi

vfront records

3 published records for vendor vfront.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 21

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

3 records
  • CVE-2019-9838
    24Monitor

    VFront 0.99.5 has stored XSS via the admin/sync_reg_tab.php azzera parameter, which is mishandled during admin/error_log.php rendering.

    MediumCVSS 6.1No exploitEPSS 1%

    vfront · vfrontJun 3, 2019

  • CVE-2019-9839
    24Monitor

    VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    vfront · vfrontJun 3, 2019

  • Multiple Cross Site Scripting (XSS) vulnerabilities exist in VFront 0.99.5 via the (1) s parameter in search_all.php and the (2) msg paramet

    MediumCVSS 6.1No exploitEPSS 1%

    vfront · vfrontNov 8, 2021