Xpand It
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Xpand It product.
RSS Feeds for Xpand It security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Xpand It products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Xpand It Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Xpand It. Xpand It did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 1 | 9.80 |
| 2023 | 3 | 7.70 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 2 | 0.00 |
It may take a day or so for new Xpand It vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Xpand It Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2023-27168 | Jan 19, 2024 |
Arbitrary File Upload in Xpand IT Write-back Manager v2.3.1 via JSPAn arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file. |
|
| CVE-2023-27172 | Dec 20, 2023 |
Xpand IT Write-back Mgr 2.3.1 Weak JWT Secret BruteForceXpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack. |
|
| CVE-2023-27170 | Oct 26, 2023 |
Directory Traversal in XpandIT WB Manager 2.3.1 via siteNameXpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter. |
|
| CVE-2023-27169 | Sep 12, 2023 |
Xpand IT WBManager 2.3.1: Hardcoded Salt Generates Predictable Sym KeyXpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation. |
|
| CVE-2019-19678 | Dec 09, 2019 |
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry pointIn "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry point via the Generic Test Definition field of a new Generic Test issue. |
|
| CVE-2019-19679 | Dec 09, 2019 |
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry pointIn "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue. |
|