📦

portal

Vendor: qpr

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 12 Total Indexed
Avg. EPSS 1.39% Exploit Prob.
Latest CVE CVE-2014-8268 Feb 01

Security Vulnerability Index

Page 1 / 2
6.4 CVSS

QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request.

EPSS: 1.35%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter.

EPSS: 1.12%
4.3 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body field.

EPSS: 1.69%