Where
-Infinity
0

Vendor Risk Score

See how bitrix24 compares to other vendors in security performance

View Risk Score →

Bitrix24 Bitrix24Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow r…

Risk 37
Severity
6.8
First published (updated )

Bitrix24 Bitrix24Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows…

Risk 37
Severity
6.8
First published (updated )

Bitrix24 Bitrix24Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 all…

Risk 37
Severity
6.8
First published (updated )

1C-Bitrix Bitrix24Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows…

Risk 37
Severity
6.8
First published (updated )

1C-Bitrix Bitrix24Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows …

Risk 37
Severity
6.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Bitrix24 Bitrix24Bitrix24 Stored Cross-Site Scripting (XSS) via File Upload

Risk 80
Severity
9.6
First published (updated )

Bitrix24 Bitrix24Bitrix24 Insecure Global Variable Extraction

Risk 86
Severity
9.8
First published (updated )

Bitrix24 Bitrix24Bitrix24 Denial-of-Service (DoS) via Improper File Stream Access

Risk 43
Severity
7.5
First published (updated )

Bitrix24 Bitrix24Bitrix24 Cross-Site Scripting (XSS) via Client-side Prototype Pollution

Risk 80
Severity
9.6
First published (updated )

Bitrix24 Bitrix24Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (2 of 2)

Risk 80
Severity
9.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Bitrix24 Bitrix24Bitrix24 Stored Cross-Site Scripting (XSS) via Improper Input Neutralization on Invoice Edit Page (1 of 2)

Risk 74
Severity
9
First published (updated )

Bitrix24 Bitrix24Bitrix24 Remote Command Execution (RCE) via Unsafe Variable Extraction

Risk 79
Severity
8.8
First published (updated )

Bitrix24 Bitrix24Bitrix24 Remote Command Execution (RCE) via Insecure Temporary File Creation

Risk 79
Severity
8.8
First published (updated )

Bitrix24 Bitrix24Infoleak

Risk 30
Severity
4.9
First published (updated )

Bitrix24 Bitrix Site ManagerBitrix Site Manager Contact Form cross site scripting

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Bitrix24 Bitrix24Input Validation

Risk 87
Severity
10
First published (updated )

Bitrix24 Bitrix FrameworkAn issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration…

Risk 38
Severity
6.5
First published (updated )

Bitrix24 Bitrix24XSS

Risk 38
Severity
6.1
First published (updated )

Bitrix24 Bitrix24SSRF

Risk 86
Severity
9.8
First published (updated )

Bitrix Bitrix Site ManagerOpen redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to re…

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203