Skip to main content

Vendor/product archive

atlassian / agiloft CVEs

Beta · best-effort

4 CVEs tagged to atlassian / agiloft1 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-35115

Published Aug 26, 2025

Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of the dow…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-35114

Published Aug 26, 2025

Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-35113

Published Aug 26, 2025

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a s…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-35112

Published Aug 26, 2025

Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and per…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1