Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kiwitcms

First CVE: Nov 21, 2022Active for: 4 yearsTotal CVEs: 11
32.0
VTI Score
Medium

Kiwitcms develops a test case management platform that, despite a narrow product portfolio, occupies a prominent position in quality assurance and testing workflows across enterprises. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in web-application input handling and resource-management weaknesses such as cross-site scripting, unrestricted file uploads, OS command injection, and insufficient rate limiting on authentication attempts. Defenders should prioritize this vendor's advisories given the critical-severity tendency and the platform's role in managing sensitive test data and CI/CD integration; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kiwitcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2022
3 years ago
Most Recent CVE
Jul 5, 2023
1,116 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-30613CRITICAL
Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control ove
Apr 24, 20239.029NONO
CVE-2023-25156CRITICAL
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page.
Feb 15, 20239.829NONO
CVE-2023-22451HIGH
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would
Jan 2, 20238.827NONO
CVE-2023-30628HIGH
Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` workflow is vulnerable to command
Apr 24, 20238.823NONO
CVE-2023-25171MEDIUM
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Passw
Feb 15, 20235.920NONO
CVE-2023-36809MEDIUM
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which
Jul 5, 20235.419NONO
CVE-2023-33977MEDIUM
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versi
Jun 6, 20235.419NONO
CVE-2023-27489MEDIUM
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files uploaded by users which could potentially contain JavaScript c
Mar 29, 20235.419NONO
CVE-2023-32686MEDIUM
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versi
May 27, 20235.418NONO
CVE-2023-30544MEDIUM
Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This pa
Apr 24, 20234.318NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
18%
18%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low8 (72.7%)
High0 (0.0%)
None3 (27.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kiwitcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kiwitcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kiwitcms's Products

View all 2 CNAs →

Top CWEs