VendorsGalaxyprojectgalaxyall versions
Vulnerabilities

Galaxyproject Galaxy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2015-10062
galaxy-data-resource Command Line Template injection
Published 2023-01-17 · Modified
9.8EPSS 0.009
CVE-2023-27578
Galaxy vulnerable to unauthorized modification of pages/visualizations due to insufficient permission check
Published 2023-03-20 · Modified
9.1EPSS 0.008
CVE-2024-42351
Possible Data Tampering & Loss of Public Datasets in Galaxy
Published 2024-09-20 · Analyzed
9.1EPSS 0.005
CVE-2022-23470
Arbitrary file access in the Galaxy data analysis platform
Published 2022-12-06 · Modified
8.6EPSS 0.008
CVE-2024-42346
Stored Cross Site Scripting (Stored XSS) in Galaxy
Published 2024-09-20 · Analyzed
7.6EPSS 0.008
CVE-2023-42812
Galaxy vulnerable to Server Side Request Forgery during data imports
Published 2023-09-22 · Modified
6.3EPSS 0.004
CVE-2018-1000516
The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow for cross-site scripting (XSS) attacks. In this form of attack, a malicious person can create a URL which, when opened by a Galaxy user or administrator, would allow the malicious user to execute arbitrary Javascript. that can result in Arbitrary JavaScript code execution. This attack appear to be exploitable via The victim must interact with component on page witch contains injected JavaScript code.. This vulnerability appears to have been fixed in v14.10.1, v15.01.
Published 2018-06-26 · Modified
6.1EPSS 0.011