Kanopi's vulnerability footprint is narrow and centers on its Next.js-based web application framework and related components. The observed weakness pattern involves permissive cross-domain security policies that fail to restrict trusted domains appropriately, a characteristic risk in client-side JavaScript frameworks where origin validation directly controls access to sensitive resources. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kanopi over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13984MEDIUM Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4 | Jan 28, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kanopi.
Media articles that mention a CVE ID that affects a product developed by Kanopi — matched by CVE ID, not by vendor name.