VendorsCinnamonkotaemonany version
Vulnerabilities

Cinnamon kotaemon any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-56527
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
Published 2025-11-18 · Analyzed
7.5EPSS 0.004
CVE-2025-56526
Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.
Published 2025-11-18 · Analyzed
6.1EPSS 0.004