VendorsCERNindicoall versions
Vulnerabilities

CERN Indico

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-33046
Indico discloses local files resulting in Remote Code Execution through LaTeX injection
Published 2026-03-23 · Analyzed
8.8EPSS 0.010
CVE-2021-30185
CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.
Published 2021-04-07 · Modified
7.5EPSS 0.010
CVE-2024-50633
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain information about other user accounts (this functionality is, in the current design, not restricted to any privileged roles such as event organizer).
Published 2025-01-16 · Analyzed
7.5EPSS 0.006
CVE-2026-25738
Indico has Server-Side Request Forgery (SSRF) in multiple places
Published 2026-02-19 · Analyzed
6.9EPSS 0.003
CVE-2025-53640
Indico vulnerable to user enumeration via API endpoint
Published 2025-07-14 · Analyzed
6.5EPSS 0.006
CVE-2026-28352
Indico missing access check in event series management API
Published 2026-02-27 · Analyzed
6.5EPSS 0.003
CVE-2024-45399
Indico has a Cross-Site-Scripting during account creation
Published 2024-09-04 · Analyzed
6.1EPSS 0.004
CVE-2023-37901
Cross-Site-Scripting via confirmation prompts
Published 2023-07-21 · Modified
5.4EPSS 0.005
CVE-2026-25739
Indico affected by Cross-Site-Scripting via material uploads
Published 2026-02-19 · Analyzed
5.4EPSS 0.003
CVE-2025-59035
Indico vulnerable to Cross-Site Scripting via LaTeX math code
Published 2025-09-10 · Analyzed
5.4EPSS 0.002
CVE-2025-59034
Indico may disclose unauthorized user details access via legacy API
Published 2025-09-10 · Analyzed
4.3EPSS 0.003