20 Total advisories
20 Vulnerabilities
0 Malware
Dependency scanning
Check whether kiwitcms is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.1
CVE-2023-36809
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
HIGH 7.7
CVE-2023-30613
Unrestricted file upload in kiwi TCMS
MEDIUM 5.4
CVE-2023-32686
kiwitcms vulnerable to stored XSS via unrestricted files upload
HIGH 8.1
CVE-2023-36809
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
HIGH 7.7
CVE-2023-30613
Unrestricted file upload in kiwi TCMS
NONE 0.0
CVE-2023-30544
kiwi TCMS has possibility for user to update email address to unverified one
HIGH 7.6
CVE-2023-27489
Kiwi TCMS Stored Cross-site Scripting via SVG file
HIGH 8.1
CVE-2023-33977
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
MEDIUM 5.4
CVE-2022-4105
Cross-site Scripting in kiwitcms
MEDIUM 5.4
CVE-2022-4105
Cross-site Scripting in kiwitcms
HIGH 7.5
CVE-2023-25171
Denial of service vulnerability on Password reset page
HIGH 7.5
CVE-2023-25156
No protection against brute-force attacks on login page
UNKNOWN
CVE-2026-49292
Kiwi TCMS's /init-db/ page renders and responds to requests after first use
HIGH 8.1
CVE-2023-33977
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
HIGH 8.8
CVE-2023-30628
CVE-2023-30628
MEDIUM 5.4
CVE-2023-32686
kiwitcms vulnerable to stored XSS via unrestricted files upload
HIGH 7.5
CVE-2023-25171
Denial of service vulnerability on Password reset page
HIGH 7.5
CVE-2023-25156
No protection against brute-force attacks on login page
NONE 0.0
CVE-2023-30544
kiwi TCMS has possibility for user to update email address to unverified one
HIGH 7.6
CVE-2023-27489
Kiwi TCMS Stored Cross-site Scripting via SVG file
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes