CVE Tools

Hyland

16 CVEs tracked since 2018. Since Feb 2018, none of them reached CISA KEV.

Hyland CVEs per month

Feb 2018 to Sep 2020. Point at a month, or focus the strip and use the arrow keys.
Hyland CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0220
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09140

Products

The products that kept showing up in Hyland's monthly top three, with their CVEs summed over those months.

  1. Onbase141 month
  2. Saperion Web Client21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Hyland.

  1. CVE-2026-58127PACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service9.8
  2. CVE-2026-58126PACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service9.8
  3. CVE-2026-26339Hyland Alfresco Transformation Service Argument Injection RCE9.8
  4. CVE-2026-26338Hyland Alfresco Transformation Service SSRF9.8
  5. CVE-2026-26337Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRF8.2
  6. CVE-2026-26336Hyland Alfresco Improper Authorization Arbitrary File Read7.5
  7. CVE-2026-26221Hyland OnBase Timer Service Unauthenticated .NET Remoting RCE9.8
  8. CVE-2025-0557Hyland Alfresco Community Edition URL s cross site scripting4.3
  9. CVE-2024-40347A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted pay...6.1
  10. CVE-2023-49964An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Inject...8.8
  11. CVE-2021-32828Regular expression Denial of Service in MooTools5.4
  12. CVE-2022-23342The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obta...5.3
  13. CVE-2020-25247An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Directory traversal exists for writing to files, as demonstrated by the FileName parameter.7.5
  14. CVE-2020-25248An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Directory traversal exists for re...7.5
  15. CVE-2020-25249An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. The server typically logs activity only w...5.3

The record

Peak rank
#38 in Sep 2020
Busiest month shown
Sep 2020, 14 CVEs
Months with a KEV entry
0 since Feb 2018
Monthly snapshots
2 since 2018
Hyland's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store