Kiteworks / Core
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-102142 | Kiteworks Core Remote Code Execution through Server-Side Template Injection | HIGH | 7.2 | Sep 30, 2026 |
| CVE-2026-102100 | Kiteworks Core stored XSS | HIGH | 8.7 | Sep 30, 2026 |
| CVE-2026-102147 | Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) | CRITICAL | 9.3 | Sep 30, 2026 |
| CVE-2026-102145 | Kiteworks Core Server-Side Request Forgery through CRLF Injection | MEDIUM | 6.6 | Sep 30, 2026 |
| CVE-2026-102096 | Kiteworks Core OS command injection | HIGH | 7.2 | Sep 30, 2026 |
| CVE-2026-102099 | Kiteworks Core arbitrary file write | HIGH | 7.2 | Sep 30, 2026 |
| CVE-2026-102093 | Kiteworks Core improper privilege management | HIGH | 7.2 | Sep 30, 2026 |
| CVE-2026-102092 | Kiteworks Core stored XSS | HIGH | 8.7 | Sep 30, 2026 |
| CVE-2026-102090 | Kiteworks Core content injection | MEDIUM | 4.3 | Sep 30, 2026 |
| CVE-2026-102098 | Kiteworks Core SQL Injection | HIGH | 7.2 | Sep 30, 2026 |
| CVE-2026-23514 | Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management | HIGH | 8.8 | Mar 25, 2026 |
Showing 26 to 35 of 35 CVEs