VendorsOkfnckanany version
Vulnerabilities

Okfn Open Knowledge Foundation CKAN any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2026-42031
CKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
Published 2026-05-13 · Analyzed
9.8EPSS 0.022
CVE-2023-32321
CKAN remote code execution and private information access via crafted resource ids
Published 2023-05-26 · Modified
9.8EPSS 0.017
CVE-2026-42032
CKAN: Unauthenticated Authorization Bypass in `datastore_search_sql`
Published 2026-05-13 · Analyzed
9.1EPSS 0.004
CVE-2023-32696
Excessive permissions for ckan user
Published 2023-05-30 · Modified
8.8EPSS 0.008
CVE-2022-43685
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.
Published 2022-11-22 · Modified
8.8EPSS 0.007
CVE-2023-22746
CKAN is vulnerable to session secret shared across instances using Docker images
Published 2023-02-03 · Modified
8.6EPSS 0.007
CVE-2026-41132
CKAN: No certificate validation on STMP connection
Published 2026-05-13 · Analyzed
7.4EPSS 0.002
CVE-2024-41675
CKAN has a Cross-site Scripting vector in the Datatables view plugin
Published 2024-08-21 · Analyzed
6.8EPSS 0.004
CVE-2023-50248
CKAN out of memory error when submitting the dataset form with a specially-crafted field
Published 2023-12-13 · Modified
6.5EPSS 0.006
CVE-2024-43371
Potential access to sensitive URLs via CKAN extensions (SSRF)
Published 2024-08-21 · Analyzed
6.5EPSS 0.004
CVE-2026-41255
CKAN: CSRF exemption primed by anonymous requests
Published 2026-05-13 · Analyzed
6.1EPSS 0.001
CVE-2021-25967
CKAN - Stored Cross-Site Scripting (XSS) via SVG File Upload
Published 2021-12-01 · Modified
5.4EPSS 0.005
CVE-2024-27097
Potential log injection in reset user endpoint in ckan
Published 2024-03-13 · Analyzed
5.3EPSS 0.004
CVE-2024-41674
CKAN may leak Solr credentials via error message in package_search action
Published 2024-08-21 · Analyzed
5.3EPSS 0.004