Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Filtered by product Xtraction
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-14902 1 Ivanti 1 Xtraction 2026-08-06 N/A 4.0 MEDIUM
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
CVE-2026-14903 1 Ivanti 1 Xtraction 2026-08-06 N/A 7.7 HIGH
Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
CVE-2026-8043 1 Ivanti 1 Xtraction 2026-06-17 N/A 9.6 CRITICAL
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.