VendorsKreawebgenealogyall versions
Vulnerabilities

Kreaweb Genealogy

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-39355
Genealogy is Missing Authorization in `TeamController::transferOwnership()` Allows Any Authenticated User to Hijack Any Team (Broken Access Control)
Published 2026-04-07 · Analyzed
9.9EPSS 0.004
CVE-2025-55287
Genealogy has a stored XSS vulnerability
Published 2025-08-18 · Analyzed
8.0EPSS 0.003
CVE-2025-55288
Genealogy has a Reflected XSS Vulnerability
Published 2025-08-18 · Analyzed
5.5EPSS 0.003