Stay in touch

Enter your email and get the latest news and researches on cybersecurity, receive invitations to private security events and conferences.

High-Tech Bridge Security Advisories

While testing and developing various vulnerability detection algorithms of ImmuniWeb®, we discovered hundreds of vulnerabilities in the most popular commercial and open source web applications and frameworks:

Security Advisories
Released Patches


Remote Code Execution in Roundcube Advisory ID: HTB23283
Last Change: January 13, 2016
CVE Reference: CVE-2015-8770
Vulnerable Version: 1.1.3
Risk Level: Medium
Two CSRF Vulnerabilities in Magento Advisory ID: HTB23270
Last Change: December 21, 2015
CVE Reference: Assigned [To be disclosed on October 4, 2017]
Vulnerable Version:
Risk Level: Medium
SQL Injection in orion.extfeedbackform Bitrix Module Advisory ID: HTB23280
Last Change: December 16, 2015
CVE Reference: CVE-2015-8355
Vulnerable Version: 2.1.2
Risk Level: Medium
RCE in Zen Cart via Arbitrary File Inclusion Advisory ID: HTB23282
Last Change: December 16, 2015
CVE Reference: CVE-2015-8352
Vulnerable Version: 1.5.4
Risk Level: Critical
Path Traversal via CSRF in bitrix.xscan Bitrix Module Advisory ID: HTB23278
Last Change: December 9, 2015
CVE Reference: CVE-2015-8357
Vulnerable Version: 1.0.3
Risk Level: Medium
PHP File Inclusion in bitrix.mpbuilder Bitrix Module Advisory ID: HTB23281
Last Change: December 9, 2015
CVE Reference: CVE-2015-8358
Vulnerable Version: 1.0.10
Risk Level: Critical
Reflected XSS in Role Scoper WordPress Plugin Advisory ID: HTB23276
Last Change: November 19, 2015
CVE Reference: CVE-2015-8353
Vulnerable Version: 1.3.66
Risk Level: Medium
Reflected XSS in Ultimate Member WordPress Plugin Advisory ID: HTB23277
Last Change: November 19, 2015
CVE Reference: CVE-2015-8354
Vulnerable Version: 1.3.28
Risk Level: Medium
RCE and SQL injection via CSRF in Horde Groupware Advisory ID: HTB23272
Last Change: November 18, 2015
CVE Reference: CVE-2015-7984
Vulnerable Version: 5.2.10
Risk Level: High
Two Reflected XSS Vulnerabilities in Calls to Action WordPress plugin Advisory ID: HTB23274
Last Change: November 4, 2015
CVE Reference: CVE-2015-8350
Vulnerable Version: 2.4.3
Risk Level: Medium