Skip to content

Known CVE

SysAid On-Prem <= 23.3.40 - XML External Entity

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

CVE-2025-2776

Critical2025CVSS 9.3CWE-611

cve2025 · sysaid · xxe · oast · kev · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website