BladexCVEs & Vulnerabilities

9 CVEs affecting Bladex products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

springblade 9
CVE-2025-70982CRITICAL

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.

26 Jan 2026
9.9
CVSS
CVE-2025-70983CRITICAL

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

23 Jan 2026
9.9
CVSS
CVE-2024-8023CRITICAL

A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

21 Aug 2024
9.8
CVSS
CVE-2024-33332HIGH

An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.

30 Apr 2024
7.5
CVSS
CVE-2023-47458CRITICAL

An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.

3 Jan 2024
9.8
CVSS
CVE-2023-40788MEDIUM

SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs

19 Sep 2023
5.3
CVSS
CVE-2023-40787CRITICAL

In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.

29 Aug 2023
9.8
CVSS
CVE-2022-27360CRITICAL

SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

5 May 2022
9.8
CVSS
CVE-2020-16165CRITICAL

The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.

30 Jul 2020
9.8
CVSS
← PrevPage 1 / 1Next →