Known Vulnerabilities for Springblade by Springblade Project
Listed below are 1 of the newest known vulnerabilities associated with "Springblade" by "Springblade Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-36765 json | An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated at... | Not Provided | 2026-04-30 | 2026-05-04 |
| CVE-2026-36764 json | A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenti... | Not Provided | 2026-04-30 | 2026-04-30 |
| CVE-2026-36763 json | A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows ... | Not Provided | 2026-04-30 | 2026-04-30 |
| CVE-2023-47458 json | An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions contro... | Not Provided | 2024-01-02 | 2026-07-05 |
| CVE-2020-16165 json | The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /a... | 9.8 - CRITICAL | 2020-07-30 | 2020-08-05 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Springblade Project | Springblade | 2.7.1 |