| CVE-2025-51629 | Hig | 0.57 | 8.8 | 0.00 | | Aug 7, 2025 | A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter. |
| CVE-2025-51628 | Hig | 0.49 | 7.5 | 0.00 | | Aug 5, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated attackers to read confidential documents via the DocumentoId parameter. |
| CVE-2025-51627 | Med | 0.42 | 6.5 | 0.00 | | Aug 5, 2025 | Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator. |