Thinkst

Canarytokens

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 24.06.2026 11:12:17
  • Zuletzt bearbeitet 24.06.2026 13:16:31

Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Canarytokens: from Docker tag sha-4116b92cb before sha...

  • EPSS 0.29%
  • Veröffentlicht 22.06.2026 13:05:53
  • Zuletzt bearbeitet 23.06.2026 15:42:44

An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links. This issue a...

  • EPSS 0.26%
  • Veröffentlicht 10.06.2026 11:35:14
  • Zuletzt bearbeitet 10.06.2026 20:13:47

An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from D...

  • EPSS 0.2%
  • Veröffentlicht 03.06.2026 14:16:35
  • Zuletzt bearbeitet 04.06.2026 16:37:27

An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render...

  • EPSS 0.4%
  • Veröffentlicht 27.02.2026 21:04:13
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Scripting vulnerability in the "PWA" Canarytoken, whereby the Canarytoken's creator can attack themselves or someone they share the link...

  • EPSS 0.38%
  • Veröffentlicht 23.07.2024 17:15:12
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook alert feature. When a Canarytoken is created, users choose to receive alerts either via email or via a w...

  • EPSS 0.33%
  • Veröffentlicht 23.07.2024 16:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can attack themselves. The creator of a slow-redirect Canarytoken c...

  • EPSS 0.63%
  • Veröffentlicht 06.03.2024 22:15:57
  • Zuletzt bearbeitet 05.12.2025 16:25:22

Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection vulnerability. This flaw can be...

  • EPSS 0.52%
  • Veröffentlicht 06.01.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 07:44:52

Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens prior to sha-fb61290. An attacker who discovers an HTTP-base...

  • EPSS 0.49%
  • Veröffentlicht 01.07.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 07:03:55

Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens. This permits an attacker who recognised an HTTP-based Canar...