Gotify is a notification server application with a niche deployment footprint, and its observed vulnerabilities center on web-page generation and input-handling weaknesses characteristic of server-side applications that accept and render user-supplied content. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gotify over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46181MEDIUM Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 contain an XSS vulnerability that allows authenticated users | Dec 29, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gotify.
Media articles that mention a CVE ID that affects a product developed by Gotify — matched by CVE ID, not by vendor name.