VYPR
Vendor

Wolterskluwer

Products
9
CVEs
12
Across products
14
Status
Private

Products

9

Recent CVEs

12
  • CVE-2021-41932HigJun 6, 2022
    risk 0.57cvss 8.8epss 0.01

    A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in complete database compromise, gaining information about other users, unauthorized access to audit data…

  • CVE-2023-49328HigDec 25, 2023
    risk 0.47cvss 7.2epss 0.01

    On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.

  • CVE-2019-10253MedSep 9, 2019
    risk 0.42cvss 6.5epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists…

  • CVE-2026-2680MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

  • CVE-2026-2679MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

  • CVE-2026-2678MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/customers' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

  • CVE-2026-2677MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

  • CVE-2026-1493MedApr 30, 2026
    risk 0.35cvss 5.4epss 0.00

    LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser. An attacker with ability to set a…

  • CVE-2023-33438MedJun 16, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2021-44035MedDec 17, 2021
    risk 0.29cvss 4.4epss 0.01

    Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files.

  • CVE-2014-9113Dec 2, 2014
    risk 0.03cvss epss 0.02

    CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX…

  • CVE-2010-3125Aug 26, 2010
    risk 0.03cvss epss 0.06

    Untrusted search path vulnerability in TeamMate Audit Management Software Suite 8.0 patch 2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc71enu.dll that is located in the same folder as a .tmx…