Kiwi
kiwitcms- Product type
- Other
- Catalog vulnerabilities
- 12
Severity across 12 analyzed records
Verify to analyze this security profile
en
As of 09/17/2026, within CyStack's analyzed data, Kiwi has 2 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Kiwi and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-55630Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase) | Exploitation statusNot confirmed | FixYes | Published09/15/2026 | SeverityInformational |
CVE-2026-54724Kiwi TCMS: Open Redirect via unvalidated next parameter in account confirmation endpoint | Exploitation statusNot known exploited | FixYes | Published09/15/2026 | SeverityMedium |
CVE-2023-36809Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox | Exploitation statusPublic exploit | FixNot confirmed | Published07/05/2023 | SeverityHigh |
CVE-2023-33977Stored cross site scripting (XSS) via unrestricted file upload in Kiwi TCMS | Exploitation statusPublic exploit | FixNot confirmed | Published06/06/2023 | SeverityHigh |
CVE-2023-32686kiwitcms vulnerable to stored XSS via unrestricted files upload | Exploitation statusNot known exploited | FixYes | Published05/27/2023 | SeverityHigh |
CVE-2023-30628Kiwi TCMS has command injection vulnerability in changelog.yml CI workflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/24/2023 | SeverityHigh |
CVE-2023-30613Kiwi TCMS unrestricted file upload vulnerability | Exploitation statusPublic exploit | FixNot confirmed | Published04/24/2023 | SeverityHigh |
CVE-2023-30544Kiwi TCMS may allow user to update email address to unverified one | Exploitation statusPublic exploit | FixNot confirmed | Published04/24/2023 | SeverityLow |
CVE-2023-27489Stored cross site scripting via SVG file upload in Kiwi TCMS | Exploitation statusNot known exploited | FixYes | Published03/29/2023 | SeverityHigh |
CVE-2023-25156Kiwi TCMS has no protection against brute-force attacks on login page | Exploitation statusNot known exploited | FixYes | Published02/15/2023 | SeverityHigh |
CVE-2023-25171Kiwi TCMS has denial of service vulnerability on Password reset page | Exploitation statusNot known exploited | FixYes | Published02/15/2023 | SeverityHigh |
CVE-2023-22451Weak password requirements in Kiwi TCMS | Exploitation statusNot known exploited | FixYes | Published01/02/2023 | SeverityMedium |