Skip to main content

Vendor/product archive

kiwitcms / kiwi_tcms CVEs

Beta · best-effort

11 CVEs tagged to kiwitcms / kiwi_tcms0 Critical, 8 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2023-36809

Published Jul 5, 2023

Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes whic…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33977

Published Jun 6, 2023

Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier vers…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32686

Published May 27, 2023

Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier vers…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30628

Published Apr 24, 2023

Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` workflow is vulnerable to command…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30613

Published Apr 24, 2023

Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control ov…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30544

Published Apr 24, 2023

Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This p…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-27489

Published Mar 29, 2023

Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files uploaded by users which could potentially contain JavaScript…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25171

Published Feb 15, 2023

Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Pass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25156

Published Feb 15, 2023

Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22451

Published Jan 2, 2023

Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which woul…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4105

Published Nov 21, 2022

A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1