CVE Browser
wire-webapp has no database deletion on client logout
wire-avs remote format string vulnerability
wire-server vulnerable to unauthorized removal of Bots from Conversations
wire-webapp contains Improper Handling of Exceptional Conditions leading to a DoS via Markdown Rendering
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppD…
Wire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account creation
Cross Site Scripting in Wire Messages
DoS vulnerability: Invalid Accent Colors
Cross Site Scripting in Wire Webapp
DoS vulnerabiliity in wire-server json parser
Improper Verification of Cryptographic Signature in wire-server
DoS vulnerability: Malformed Resource Identifiers
Use of Externally-Controlled Format String in wire-avs
Expired Ephemeral Messages not reliably removed in wire-webapp
Account takeover when having only access to a user's short lived token in wire-server
Mandatory encryption at rest can be bypassed (UI) in Wire app
Account takeover when having only access to a user's short lived token
CORS `Access-Control-Allow-Origin` settings are too lenient
Certificate pinning is not enforced on the web socket connection
XSS through createObjectURL
Unsafe loopback forwarding interface in Restund
Asset DoS vulnerability
Verified groups not reliable
Entering code in App Lock modal sends input to conversation
Bulk list client endpoint exposes too much metadata about a client
Showing 1 to 25 CVEs · page 1 (more available)