Skip to main content

Vendor archive

wire CVEs

Beta · best-effort

29 CVEs tagged to vendor wire6 Critical, 9 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2025-48066

Published May 22, 2025

wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the c…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48221

Published Nov 20, 2023

wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to versions 9.2.22 and 9.3.5, a remote format string vulnerabilit…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22737

Published Jan 28, 2023

wire-server provides back end services for Wire, a team communication and collaboration platform. Prior to version 2022-12-09, every member of a Conversation can remove a Bot from…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39380

Published Jan 27, 2023

Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of Exceptional Conditions. In the wire-webapp, certain combinations of M…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43673

Published Nov 18, 2022

Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of time) from the AppData\Roaming\Wire\Ind…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31122

Published Oct 18, 2022

Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain detai…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29168

Published Jun 25, 2022

Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient escaping when rendering `@mentions` in the wire-webapp. If a…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31009

Published Jun 23, 2022

wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by caus…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24799

Published Apr 20, 2022

wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility o…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41119

Published Apr 13, 2022

Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial of service attack via a crafted object causing a hash collis…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23610

Published Mar 16, 2022

wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-01-27 release, it was possible to craft DSA Signatures to b…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-23625

Published Mar 11, 2022

Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client comple…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41193

Published Mar 1, 2022

wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to ca…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-23605

Published Feb 4, 2022

Wire webapp is a web client for the wire messaging protocol. In versions prior to 2022-01-27-production.0 expired ephemeral messages were not reliably removed from local chat hist…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41100

Published Oct 4, 2021

Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address change of a user with only th…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41094

Published Oct 4, 2021

Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the a…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41093

Published Oct 4, 2021

Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by changing the email. This issue…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41101

Published Sep 30, 2021

wire-server is an open-source back end for Wire, a secure collaboration platform. Before version 2.106.0, the CORS ` Access-Control-Allow-Origin ` header set by `nginz` is set for…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32755

Published Jul 13, 2021

Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries for the iOS implementation of Wire. In the 3.82 version of t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32683

Published Jun 15, 2021

wire-webapp is the web version of Wire, an open-source messenger. A cross-site scripting vulnerability exists in wire-webapp prior to version 2021-06-01-production.0. If a user is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21382

Published Jun 11, 2021

Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32666

Published Jun 3, 2021

wire-ios is the iOS version of Wire, an open-source secure messaging app. In wire-ios versions 3.8.0 and prior, a vulnerability exists that can cause a denial of service between u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32665

Published Jun 3, 2021

wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 and earlier have a bug in which a conversation could be incorrectly set to "unver…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21400

Published Apr 2, 2021

wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being prompted to enter the app-lock…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21396

Published Mar 26, 2021

wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16 and before version 2021-03-02, the client metadata of all…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2