Syncfusion
syncfusion
7 CVEs • 4 products
Products (4)
Click to collapseToggle
Products (4)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Syncfusion 1Standalone Report Designer Jul 28, 2026 Jul 23, 2026 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory...Show more |
1Syncfusion 1Standalone Report Designer Jul 28, 2026 Jul 23, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server f...Show more |
1Syncfusion 1Standalone Report Designer Jul 28, 2026 Jul 23, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server fil...Show more |
1Syncfusion 1Standalone Report Designer Jul 28, 2026 Jul 23, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server file...Show more |
SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message. |
1Syncfusion 1Ej2 Aspcore File Provider Jun 17, 2026 Jul 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or uplo...Show more |
1Syncfusion 1Nodejs File System Provider Jun 17, 2026 Jul 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any...Show more |