PatchSiren

Bimser Solution Software Trade Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Bimser Solution Software Trade Inc. CVE published 2026-09-28

CVE-2026-85134

This debrief provides an executive overview of CVE-2026-85134, an unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System. The vulnerability class allows for potential arbitrary code execution and web shell upload. The affected product or component is EBA Plus Document and Workflow Management System, with version [truncated]

MEDIUM Bimser Solution Software Trade Inc. CVE published 2026-09-28

CVE-2026-82969

A cross-site scripting vulnerability exists in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System, affecting versions from 6.7.141 to before 10.0.11. This issue allows for Stored XSS, enabling attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data breaches. Defenders should assess exposure and prioritize remediation based [truncated]

MEDIUM Bimser Solution Software Trade Inc. CVE published 2026-09-28

CVE-2026-82915

CVE-2026-82915 is a Path Traversal vulnerability in the EBA Plus Document and Workflow Management System, affecting versions from 6.7.141 to before 10.0.11. Defenders should assess exposure, prioritize remediation, and verify system versions. The vulnerability allows attackers to potentially access unauthorized files or directories, emphasizing the need for system version verification and potential path t [truncated]