Kallithea is a self-hosted repository management and collaboration platform that serves as a source-control hub in development environments, though it maintains a narrow product footprint. The vendor's observed vulnerability exposure remains focused and modest in scope; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kallithea Scm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3691HIGH Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method. | Apr 24, 2017 | 8.8 | 27 | NO | NO |
CVE-2015-5285MEDIUM CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from paramete | Oct 29, 2015 | 5.0 | 24 | NO | YES |
CVE-2015-0276HIGH Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2. | Sep 21, 2017 | 8.8 | 22 | NO | NO |
CVE-2015-0260MEDIUM RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method. | Feb 16, 2015 | 4.0 | 17 | NO | NO |
CVE-2015-1864MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) | Sep 19, 2017 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kallithea Scm.
Media articles that mention a CVE ID that affects a product developed by Kallithea Scm — matched by CVE ID, not by vendor name.