CVE-2026-24756
- EPSS 0.15%
- Veröffentlicht 01.06.2026 21:51:04
- Zuletzt bearbeitet 22.07.2026 19:10:00
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resources belonging to other users due to insufficient a...
CVE-2026-24755
- EPSS 0.14%
- Veröffentlicht 01.06.2026 21:49:22
- Zuletzt bearbeitet 22.07.2026 19:10:00
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify permissions on resources belonging to other users due to...
CVE-2026-24754
- EPSS 0.14%
- Veröffentlicht 01.06.2026 21:46:56
- Zuletzt bearbeitet 22.07.2026 19:10:00
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to ver...
CVE-2026-24753
- EPSS 0.17%
- Veröffentlicht 01.06.2026 21:45:59
- Zuletzt bearbeitet 22.07.2026 19:10:00
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resources belonging to other users due to insufficient a...
CVE-2026-24752
- EPSS 0.28%
- Veröffentlicht 01.06.2026 21:43:25
- Zuletzt bearbeitet 22.07.2026 19:10:00
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9....
CVE-2026-24751
- EPSS 0.29%
- Veröffentlicht 01.06.2026 18:50:07
- Zuletzt bearbeitet 22.07.2026 08:10:00
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9....
CVE-2026-23638
- EPSS 0.18%
- Veröffentlicht 01.06.2026 18:11:35
- Zuletzt bearbeitet 22.07.2026 07:10:00
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of fo...
CVE-2026-29092
- EPSS 0.24%
- Veröffentlicht 25.03.2026 16:59:55
- Zuletzt bearbeitet 27.03.2026 19:01:19
Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorize...
CVE-2026-23636
- EPSS 0.99%
- Veröffentlicht 25.03.2026 16:58:36
- Zuletzt bearbeitet 27.03.2026 19:13:44
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an Unrestricted Upload of File with Dangerous Type due to a missing validation. Upgrade Kiteworks to ver...
CVE-2026-23635
- EPSS 0.32%
- Veröffentlicht 25.03.2026 16:57:19
- Zuletzt bearbeitet 27.03.2026 19:16:29
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could potentially lead to Unprotected Transport of Credentials under certain circumstances. Upgrade Kitewo...