Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-42097 | Sparx Pro Cloud Server requires authentication based on requested URL. Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. NVD description · AI analysis pending | 9.3 group max | <1% | PoC |
| — | |
| CVE-2025-15625 | Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. NVD description · AI analysis pending | 9.5 group max | <1% |
| — | ||
| CVE-2025-15621 | Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication NVD description · AI analysis pending | 5.7 | <1% |
| — | ||
| CVE-2022-47072 | SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classif SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box.. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — |