Skip to main content

Vendor/product archive

owasp / defectdojo CVEs

Beta · best-effort

2 CVEs tagged to owasp / defectdojo0 Critical, 1 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-3816

Published Mar 9, 2026

A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQub…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
33.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-48171

Published Aug 12, 2024

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1