Ethyca develops Fides, a privacy-management and data-governance platform designed to help organizations handle sensitive data discovery, consent, and compliance workflows. Despite a narrow product portfolio, the platform's role in processing and exposing sensitive data across enterprise infrastructure places it prominently in the security landscape, and its vulnerabilities carry a meaningful share reaching critical severity. The recurring weakness classes reflect the platform's web-facing architecture and data-handling responsibilities: information-exposure flaws, code-injection vectors, cross-site scripting, resource-consumption issues, and client-side security enforcement gaps recur across the product. Defenders deploying this vendor's platform should prioritize patches addressing data-exposure and injection issues, as misconfigurations or unpatched instances can propagate sensitive data through downstream compliance and privacy systems; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ethyca over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48224CRITICAL Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in c | Nov 15, 2023 | 9.1 | 28 | NO | NO |
CVE-2024-38537CRITICAL Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domain | Jul 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-57817HIGH Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize s | Sep 8, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-57816HIGH Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, p | Sep 8, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-52008HIGH Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak | Nov 26, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-31223MEDIUM Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to commun | Jul 3, 2024 | 5.3 | 23 | NO | YES |
CVE-2023-36827HIGH Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in c | Jul 5, 2023 | 7.5 | 23 | NO | NO |
CVE-2025-57815MEDIUM Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lac | Sep 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-45053HIGH Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitiza | Sep 4, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-46124HIGH Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in co | Oct 25, 2023 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ethyca.
Media articles that mention a CVE ID that affects a product developed by Ethyca — matched by CVE ID, not by vendor name.