Known Vulnerabilities for Windmill by Windmill Project
Listed below are 1 of the newest known vulnerabilities associated with "Windmill" by "Windmill Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-47107 json | Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where... | Not Provided | 2026-05-19 | 2026-07-14 |
| CVE-2026-23696 json | Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management... | Not Provided | 2026-04-07 | 2026-07-14 |
| CVE-2022-31519 json | The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function... | 9.3 - CRITICAL | 2022-07-11 | 2022-07-15 |