28 Total advisories
28 Vulnerabilities
0 Malware

Dependency scanning

Check whether ckan is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
PyPI

CVE-2026-42031

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

UNKNOWN
PyPI

CVE-2026-42032

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

MEDIUM 6.8
PyPI

CVE-2024-41675

CKAN has Cross-site Scripting vector in the Datatables view plugin

HIGH 7.3
PyPI

CVE-2025-24372

CKAN has an XSS vector in user uploaded images in group/org and user profiles

MEDIUM 4.5
PyPI

CVE-2024-43371

Potential access to sensitive URLs via CKAN extensions (SSRF)

MEDIUM 6.1
PyPI

CVE-2025-64100

CKAN vulnerable to fixed session IDs

MEDIUM 5.3
PyPI

CVE-2024-41674

CKAN may leak Solr credentials via error message in package_search action

MEDIUM 6.3
PyPI

CVE-2025-54384

CKAN vulnerable to stored XSS in resource description

MEDIUM 6.1
PyPI

CVE-2025-64100

CKAN vulnerable to fixed session IDs

MEDIUM 6.3
PyPI

CVE-2025-54384

CKAN vulnerable to stored XSS in resource description

MEDIUM 5.3
PyPI

CVE-2024-41674

CKAN may leak Solr credentials via error message in package_search action

MEDIUM 4.5
PyPI

CVE-2023-50248

Out of memory error when submitting the dataset form with a specially-crafted field

MEDIUM 6.8
PyPI

CVE-2024-41675

CKAN has Cross-site Scripting vector in the Datatables view plugin

MEDIUM 4.5
PyPI

CVE-2024-43371

Potential access to sensitive URLs via CKAN extensions (SSRF)

MEDIUM 4.3
PyPI

CVE-2024-27097

Potential log injection in reset user endpoint in CKAN

HIGH 7.3
PyPI

CVE-2025-24372

CKAN has an XSS vector in user uploaded images in group/org and user profiles

CRITICAL 9.8
PyPI

CVE-2023-32321

Ckan remote code execution and private information access via crafted resource ids

CRITICAL 9.8
PyPI

CVE-2023-32321

Ckan remote code execution and private information access via crafted resource ids

UNKNOWN
PyPI

CVE-2022-43685

CVE-2022-43685

UNKNOWN
PyPI

CVE-2026-42031

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

MEDIUM 6.1
PyPI

CVE-2026-41255

CKAN has CSRF exemption primed by anonymous requests

UNKNOWN
PyPI

CVE-2026-42032

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

UNKNOWN
PyPI

CVE-2026-41132

CKAN has no certificate validation on STMP connection

HIGH 8.8
PyPI

CVE-2022-43685

CKAN contains Improper Authentication leading to account takeover

MEDIUM 5.4
PyPI

CVE-2021-25967

Cross-site Scripting in CKAN

MEDIUM 4.3
PyPI

CVE-2024-27097

Potential log injection in reset user endpoint in CKAN

MEDIUM 4.5
PyPI

CVE-2023-50248

Out of memory error when submitting the dataset form with a specially-crafted field

UNKNOWN
PyPI

CVE-2021-25967

CVE-2021-25967

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes