Vulnerabilities (CVE)

Filtered by vendor Kagilum Subscribe
Filtered by product Icescrum
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-60785 1 Kagilum 1 Icescrum 2026-02-04 N/A 8.8 HIGH
A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a crafted HTML page.
CVE-2025-60786 1 Kagilum 1 Icescrum 2025-12-23 N/A 8.8 HIGH
A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip file.