Hotcrp is a specialized conference-management platform used in academic peer-review workflows, with vulnerabilities centered on the single product and rooted in web-application input handling. The durable signal reflects cross-site scripting, improper input validation, and data-exposure issues typical of web-facing administrative systems; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hotcrp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23836HIGH HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to tri | Jan 19, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-25156MEDIUM HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all types with inline Content-Disposition, causing them to be re | Jan 30, 2026 | 6.3 | 22 | NO | NO |
CVE-2026-23878MEDIUM HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02c984b4a0, authors with at leas | Jan 19, 2026 | 6.5 | 22 | NO | NO |
CVE-2022-4819MEDIUM A vulnerability was found in HotCRP. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The att | Dec 28, 2022 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hotcrp.
Media articles that mention a CVE ID that affects a product developed by Hotcrp — matched by CVE ID, not by vendor name.