Cinnamon's vulnerability footprint centers on Kotaemo, a document-management and knowledge-base product, with observed weaknesses clustering around data-handling and input-validation issues including improper compression handling, cross-site scripting, and plaintext credential storage. This represents a narrow vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cinnamon over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56527HIGH Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage. | Nov 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-63914MEDIUM An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. A | Nov 24, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-56526MEDIUM Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF. | Nov 18, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cinnamon.
Media articles that mention a CVE ID that affects a product developed by Cinnamon — matched by CVE ID, not by vendor name.