20 Total advisories
20 Vulnerabilities
0 Malware

Dependency scanning

Check whether kiwitcms is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.1
PyPI

CVE-2023-36809

Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox

HIGH 7.7
PyPI

CVE-2023-30613

Unrestricted file upload in kiwi TCMS

MEDIUM 5.4
PyPI

CVE-2023-32686

kiwitcms vulnerable to stored XSS via unrestricted files upload

HIGH 8.1
PyPI

CVE-2023-36809

Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox

HIGH 7.7
PyPI

CVE-2023-30613

Unrestricted file upload in kiwi TCMS

NONE 0.0
PyPI

CVE-2023-30544

kiwi TCMS has possibility for user to update email address to unverified one

HIGH 7.6
PyPI

CVE-2023-27489

Kiwi TCMS Stored Cross-site Scripting via SVG file

HIGH 8.1
PyPI

CVE-2023-33977

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

MEDIUM 5.4
PyPI

CVE-2022-4105

Cross-site Scripting in kiwitcms

MEDIUM 5.4
PyPI

CVE-2022-4105

Cross-site Scripting in kiwitcms

HIGH 7.5
PyPI

CVE-2023-25171

Denial of service vulnerability on Password reset page

HIGH 7.5
PyPI

CVE-2023-25156

No protection against brute-force attacks on login page

UNKNOWN
PyPI

CVE-2026-49292

Kiwi TCMS's /init-db/ page renders and responds to requests after first use

HIGH 8.1
PyPI

CVE-2023-33977

kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload

HIGH 8.8
PyPI

CVE-2023-30628

CVE-2023-30628

MEDIUM 5.4
PyPI

CVE-2023-32686

kiwitcms vulnerable to stored XSS via unrestricted files upload

HIGH 7.5
PyPI

CVE-2023-25171

Denial of service vulnerability on Password reset page

HIGH 7.5
PyPI

CVE-2023-25156

No protection against brute-force attacks on login page

NONE 0.0
PyPI

CVE-2023-30544

kiwi TCMS has possibility for user to update email address to unverified one

HIGH 7.6
PyPI

CVE-2023-27489

Kiwi TCMS Stored Cross-site Scripting via SVG file

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes