VendorsAccellionkiteworksall versions
Vulnerabilities

Accellion Kiteworks

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2021-31586
Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.
Published 2021-06-23 · Modified
8.8EPSS 0.441
CVE-2026-28269
Kiteworks Core has an OS Command Injection
Published 2026-02-26 · Analyzed
8.8EPSS 0.028
CVE-2026-23514
Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
Published 2026-03-25 · Analyzed
8.8EPSS 0.010
CVE-2025-53939
Kiteworks Core is vulnerable to Improper Input Validation
Published 2025-11-29 · Analyzed
8.8EPSS 0.007
CVE-2026-24782
Kiteworks Secure Data Forms has a SQL Injection vulnerability
Published 2026-06-01 · Analyzed
8.8EPSS 0.007
CVE-2026-24751
Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting
Published 2026-06-01 · Analyzed
8.2EPSS 0.003
CVE-2026-24752
Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting
Published 2026-06-01 · Analyzed
8.2EPSS 0.003
CVE-2026-28272
Kiteworks Email Protection Gateway has a Cross-site Scripting vulnerability
Published 2026-02-27 · Analyzed
8.1EPSS 0.004
CVE-2026-24750
Kiteworks Secure Data Forms vulnerable to Cross-site Scripting
Published 2026-03-25 · Analyzed
7.6EPSS 0.002
CVE-2026-29092
Kiteworks Email Protection Gateway has an Insufficient Session Expiration
Published 2026-03-25 · Analyzed
7.5EPSS 0.003
CVE-2026-28270
Kiteworks Core has an Unrestricted Upload of File with Dangerous Type
Published 2026-02-27 · Analyzed
7.2EPSS 0.021
CVE-2026-23636
Kiteworks Secure Data Forms is vulnerable to an Unrestricted Upload of File with Dangerous Type
Published 2026-03-25 · Analyzed
7.2EPSS 0.010
CVE-2021-31585
Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH passwords that allow local access.
Published 2021-06-23 · Modified
6.7EPSS 0.009
CVE-2017-9421
Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
Published 2018-05-24 · Modified
6.5EPSS 0.011
CVE-2026-28271
Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)
Published 2026-02-27 · Analyzed
6.5EPSS 0.005
CVE-2026-23635
Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials
Published 2026-03-25 · Analyzed
6.5EPSS 0.003
CVE-2026-23638
Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key
Published 2026-06-01 · Analyzed
6.5EPSS 0.002
CVE-2026-24753
Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key
Published 2026-06-01 · Analyzed
6.5EPSS 0.002
CVE-2026-24755
Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key
Published 2026-06-01 · Analyzed
5.4EPSS 0.001
CVE-2026-24754
Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting
Published 2026-06-01 · Analyzed
5.4EPSS 0.001
CVE-2026-24756
Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key
Published 2026-06-01 · Analyzed
4.3EPSS 0.002
CVE-2026-24761
Kiteworks Secure Data Forms is vulnerable to Authorization Bypass Through User-Controlled Key
Published 2026-06-01 · Analyzed
4.3EPSS 0.001