Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi kiwitcms Security Advisories

Loading...
High
GSA_kwCzR0hTQS1qcGd3LTJyOW0tOHFmd84AA0OU
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 10 months ago
High
GSA_kwCzR0hTQS0yZnFtLW00cjItZmg5OM4AAzr5
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 11 months ago
Moderate
GSA_kwCzR0hTQS14N2MyLTd3dmctanB4N84AAza-
kiwitcms vulnerable to stored XSS via unrestricted files upload
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 11 months ago
High
GSA_kwCzR0hTQS1md2NmLTc1M3YtZmdjas4AAy8_
Unrestricted file upload in kiwi TCMS
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 12 months ago
Low
GSA_kwCzR0hTQS03eDZxLTN2M20tY3dqZ84AAy8N
kiwi TCMS has possibility for user to update email address to unverified one
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 12 months ago
High
GSA_kwCzR0hTQS0yd2NyLTg3d2YtY2Y5as4AAyds
Kiwi TCMS Stored Cross-site Scripting via SVG file
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
High
GSA_kwCzR0hTQS03OTY4LWg0bTQtZ2htOc4AAxpr
No protection against brute-force attacks on login page
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
High
GSA_kwCzR0hTQS03ajloLTNqeGYtM3ZyZs4AAxpq
Denial of service vulnerability on Password reset page
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS1oZjk0LThteDUtMnZ2as4AAv-5
Cross-site Scripting in kiwitcms
Ecosystems: pypi
Packages: kiwitcms
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
Statistics
Advisories: 17,459
Packages: 8,116
Repositories: 2
Ecosystems: 12
Filter by Package
tensorflow 432 tensorflow-cpu 387 tensorflow-gpu 384 django 79 apache-airflow 77 ansible 57 apache-superset 48 rdiffweb 42 Pillow 41 plone 38 Plone 36 matrix-synapse 34 vyper 32 mlflow 30 opencv-contrib-python 30 opencv-python 30 Django 21 langchain 18 PaddlePaddle 17 cobbler 17 notebook 15 cryptography 15 paddlepaddle 15 modoboa 14 pillow 14 gradio 14 pyload-ng 13 pyftpdlib 13 nova 13 keystone 12 vantage6 12 OctoPrint 12 neutron 12 onionshare-cli 11 glance 11 urllib3 11 twisted 11 calibreweb 11 salt 10 Flask-AppBuilder 10 wagtail 9 waitress 9 kiwitcms 9 Zope 9 aiohttp 9 zope 9 ethyca-fides 9 opencv-contrib-python-headless 9 opencv-python-headless 9 moin 8 aubio 8 numpy 8 label-studio 8 nautobot 7 pysaml2 7 scrapy 7 pip 7 matrix-sydent 7 lief 7 jupyter-server 7 swift 7 python-keystoneclient 7 apache-airflow-providers-apache-hive 6 mailman 6 Zope2 6 lxml 6 tuf 6 pgadmin4 6 inventree 6 ipython 6 web2py 6 mindsdb 6 graphite-web 6 Products.CMFPlone 5 roundup 5 pyspark 5 saleor 5 feedparser 5 sentry 5 requests 5 paramiko 5 horizon 5 bleach 5 whoogle-search 5 ckan 5 python-gnupg 5 werkzeug 4 yt-dlp 4 omero-web 4 qutebrowser 4 markdown2 4 starlette 4 nvflare 4 ansible-core 4 datasette 4 nltk 4 Jinja2 4 GitPython 4 keylime 4 reportlab 4 trytond 4 Pygments 4 Flask-Security-Too 4 buildbot 4 grpc 4 oauthenticator 4 grpcio 4 httpie 4 jupyterhub 4 transformers 4 PyPDF2 4 FreeTAKServer-UI 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 aws-iot-device-sdk-v2 4 awsiotsdk 4 pretix 4 bottle 4 esphome 4 indico 3 sqlparse 3 keyring 3 wger 3 asyncua 3 apache-iotdb 3 indy-node 3 aim 3 rsa 3 fava 3 zenml 3 gerapy 3 django-helpdesk 3 bitlyshortener 3 pywasm3 3 cinder 3 apache-airflow-providers-apache-spark 3 Products.PluggableAuthService 3 barbican 3 ecdsa 3 flask 3 plone.supermodel 3 plone.app.dexterity 3 plone.app.theming 3 apache-libcloud 3 sickrage 3 io.grpc:grpc-protobuf 3 pyarrow 3 asyncssh 3 ray 3 tornado 3 torchserve 3 jwcrypto 3 onnx 3 Werkzeug 3 copyparty 3 Weblate 3 ujson 3 streamlit 3 ryu 3 jupyterlab 3 poetry 3 localstack 3 mayan-edms 3 pandasai 3 mistune 3 protobuf 3 tripleo-heat-templates 3 pyyaml 3 openvpn-monitor 3 plone.app.event 3 Keystone 3 docassemble.webapp 3 mitmproxy 3 quokka 3 ansible-runner 3 slixmpp 3 clearml 3 archivy 2 langchain-core 2 parlai 2 dtale 2 scout-browser 2 webargs 2 cabot 2 petl 2 websockets 2 untangle 2 logilab-common 2 py 2 Google.Protobuf 2 google/protobuf 2 github.com/protocolbuffers/protobuf 2 httplib2 2 djblets 2 certifi 2 pycrypto 2 tlslite-ng 2 wasm3 2 ctx 2 python-ldap 2 tripleo-ansible 2