VYPR

Kiteworks

by Kiteworks

CVEs (44)

  • CVE-2026-102107MedSep 30, 2026
    risk 0.30cvss 4.6epss —

    Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account.…

  • CVE-2026-102090MedSep 30, 2026
    risk 0.28cvss 4.3epss —

    Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase…

  • CVE-2026-24756MedJun 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resources belonging to other users due to insufficient authorization checks on…

  • CVE-2026-24761LowJun 1, 2026
    risk 0.24cvss 3.7epss 0.00

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to access metadata of resources belonging to other users due to insufficient authorization…

Page 3 of 3