CVE-2020-26677High· 8.8▾ TwilightAny user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
vfairs = 3.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-26680Medium· 5.4In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload
CVE-2020-26679Medium· 4.3vFairs 3.3 is affected by Insecure Permissions
CVE-2020-26678High· 8.8vFairs 3.3 is affected by Remote Code Execution
CVE-2025-13811Medium· 6.3A vulnerability was determined in jsnjfz WebStack-Guns 1.0
CVE-2025-13788High· 7.3A vulnerability has been found in Chanjet CRM up to 20251106
CVE-2023-7299Medium· 6.3A vulnerability was found in DataGear up to 4.60