Known Vulnerabilities for products from Kallithea-scm
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Kallithea-scm".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2016-3691 json | Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method. | Not Provided | 2017-04-24 | 2025-04-20 |
| CVE-2015-5285 json | CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTT... | Not Provided | 2015-10-29 | 2026-05-06 |
| CVE-2015-1864 json | Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attack... | 5.4 - MEDIUM | 2017-09-19 | 2020-05-28 |
| CVE-2015-0276 json | Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2. | 8.8 - HIGH | 2017-09-21 | 2020-05-28 |
| CVE-2015-0260 json | RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information... | Not Provided | 2015-02-16 | 2026-05-06 |
Known software with vulnerabilities from Kallithea-scm
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Kallithea-scm | Kallithea | 0.1 |