Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. PlexTrac/
  3. PlexTrac Pentest Reporting

PlexTrac Pentest Reporting

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 11 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Pentest reporting & exposure mgmt platform for vulnerability remediation

by PlexTrac · plextrac.com · source ↗

Known CVEs (11)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2024-12687 ↗CRITICAL 9.82024

    Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11839 ↗HIGH 7.52024

    Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11838 ↗CRITICAL 9.82024

    External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocumented API endpoint.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11837 ↗CRITICAL 9.82024

    Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac  allows N1QL Injection.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11836 ↗HIGH 7.52024

    Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11835 ↗HIGH 7.52024

    Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11834 ↗CRITICAL 9.12024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11833 ↗CRITICAL 9.12024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2022-37146 ↗MEDIUM 5.32022

    The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login …

  • CVE-2022-37145 ↗HIGH 7.52022

    The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacke…

  • CVE-2022-37144 ↗HIGH 8.82022

    The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can brutef…

Materials

11

Datasheets

  • PlexTrac SecurityFAQ OnePager 05 10 2024 ↗
  • Hack Pentesting Routine WP ↗
  • CRA Purple Teaming Report ↗
  • Consultant Time Suck ↗
  • Cybersecurity Talent Shortage ↗
  • 2024 0625 Enterprise Cyber Risk Catalog ↗
  • Pillars ↗
  • Pitfalls ↗
  • Supercharge Your Pentesting Life Cycle ↗
  • Enterprise Use Case Risk Based Prioritization ↗

Case studies

  • 25 12 17 ControlGap Case Study ↗

Other Breach & Attack Simulation / Pen Testing products

see all →
  • A Security · A Security
  • AIM Intelligence AIM Red · AIM Intelligence
  • AWS Security Agent · Amazon Web Services, Inc.
  • Advanced Data Pilfering · Horizon3.ai
  • Adversa AI Continuous AI Red Teaming LLM · Adversa AI
  • Aether AI · Aether AI
  • Agent Turing · PrivaSapien
  • Aikido Attack · Aikido Security