Fides
Vendor:
First CVE: Jul 5, 2023 · Active for 3 years
20
Total CVEs
More Total CVEs than 94% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fides over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 5, 2023
3 years ago
Most Recent CVE
Sep 8, 2025
319 days ago
CVE Severity & Scoring
Fides20 CVEs
50%
35%
10%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (95.0%)
High1 (5.0%)
Unknown0 (0.0%)
User Interaction
None17 (85.0%)
Unknown0 (0.0%)
Required3 (15.0%)
Privileges Required
Low4 (20.0%)
High6 (30.0%)
None10 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48224CRITICAL Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in c | Nov 15, 2023 | 9.1 | 28 | NO | NO |
CVE-2024-38537CRITICAL Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domain | Jul 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-57817HIGH Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize s | Sep 8, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-57816HIGH Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, p | Sep 8, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-52008HIGH Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak | Nov 26, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-31223MEDIUM Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration environment variable used by the Fides Privacy Center to commun | Jul 3, 2024 | 5.3 | 23 | NO | YES |
CVE-2023-36827HIGH Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in c | Jul 5, 2023 | 7.5 | 23 | NO | NO |
CVE-2025-57815MEDIUM Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lac | Sep 8, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-45053HIGH Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitiza | Sep 4, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-46124HIGH Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in co | Oct 25, 2023 | 7.2 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Fides
Top CWEs
Versions
No cataloged versions.