Indico
Vendor:
First CVE: Apr 7, 2021 · Active for 5 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Indico over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 7, 2021
5 years ago
Most Recent CVE
Mar 23, 2026
123 days ago
CVE Severity & Scoring
Indico11 CVEs
73%
27%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (63.6%)
Unknown0 (0.0%)
Required4 (36.4%)
Privileges Required
Low7 (63.6%)
High0 (0.0%)
None4 (36.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33046HIGH Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to vulnerabilities in TeXLive and | Mar 23, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-28352MEDIUM Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event | Feb 27, 2026 | 6.5 | 23 | NO | NO |
CVE-2021-30185HIGH CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link. | Apr 7, 2021 | 7.5 | 22 | NO | NO |
CVE-2026-25739MEDIUM Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting whe | Feb 19, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-59035MEDIUM Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a Cross-Site-Scripting vulnerabili | Sep 10, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-53640MEDIUM Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint use | Jul 14, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-50633HIGH A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/princi | Jan 16, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-59034MEDIUM Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could | Sep 10, 2025 | 4.3 | 18 | NO | NO |
CVE-2024-45399MEDIUM Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indico prior to version 3.3.4, corresponding to Flask-Multipass | Sep 4, 2024 | 6.1 | 18 | NO | NO |
CVE-2026-25738MEDIUM Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to server-side request forg | Feb 19, 2026 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Indico
Top CWEs
Versions
No cataloged versions.