VendorsTencentweknoraany version
Vulnerabilities

Tencent Weknora any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-30861
WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation
Published 2026-03-07 · Analyzed
9.9EPSS 0.025
CVE-2026-22688
WeKnora has Command Injection in MCP stdio test
Published 2026-01-10 · Analyzed
9.9EPSS 0.020
CVE-2026-30860
WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
Published 2026-03-07 · Analyzed
9.9EPSS 0.007
CVE-2026-22687
WeKnora vulnerable to SQL Injection
Published 2026-01-10 · Modified
9.8EPSS 0.004
CVE-2026-30855
WeKnora: Broken Access Control in Tenant Management
Published 2026-03-07 · Analyzed
8.8EPSS 0.005
CVE-2026-30856
WeKnora: Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection
Published 2026-03-07 · Analyzed
7.6EPSS 0.003
CVE-2026-30858
WeKnora: DNS Rebinding Vulnerability in web_fetch Tool Allows SSRF to Internal Resources
Published 2026-03-07 · Analyzed
7.5EPSS 0.005
CVE-2026-30247
WeKnora: SSRF via Redirection
Published 2026-03-07 · Analyzed
7.5EPSS 0.004
CVE-2026-8786
Tencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorization
Published 2026-05-18 · Analyzed
6.5EPSS 0.004
CVE-2026-30859
WeKnora: Broken Access Control - Cross-Tenant Data Exposure
Published 2026-03-07 · Analyzed
6.5EPSS 0.004
CVE-2026-30857
WeKnora: Unauthorized Cross‑Tenant Knowledge Base Cloning
Published 2026-03-07 · Analyzed
5.3EPSS 0.003