Bugsink is a focused error-tracking and bug-management platform whose vulnerability profile centers on input-handling issues in its web interface, notably improper input validation and cross-site scripting weaknesses. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bugsink over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40162HIGH Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with | Apr 10, 2026 | 7.1 | 25 | NO | NO |
CVE-2026-27614MEDIUM Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in | Feb 25, 2026 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bugsink.
Media articles that mention a CVE ID that affects a product developed by Bugsink — matched by CVE ID, not by vendor name.