VendorsPantselkongaall versions
Vulnerabilities

Pantsel Konga

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-39846
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
Published 2023-08-16 · Modified
9.8EPSS 0.011
CVE-2024-34243
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
Published 2024-05-14 · Analyzed
5.4EPSS 0.004