Kiwitcms develops a test case management platform that, despite a narrow product portfolio, occupies a prominent position in quality assurance and testing workflows across enterprises. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in web-application input handling and resource-management weaknesses such as cross-site scripting, unrestricted file uploads, OS command injection, and insufficient rate limiting on authentication attempts. Defenders should prioritize this vendor's advisories given the critical-severity tendency and the platform's role in managing sensitive test data and CI/CD integration; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kiwitcms over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30613CRITICAL Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control ove | Apr 24, 2023 | 9.0 | 29 | NO | NO |
CVE-2023-25156CRITICAL Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. | Feb 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-22451HIGH Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would | Jan 2, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-30628HIGH Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior,
the `changelog.yml` workflow is vulnerable to command | Apr 24, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-25171MEDIUM Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Passw | Feb 15, 2023 | 5.9 | 20 | NO | NO |
CVE-2023-36809MEDIUM Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which | Jul 5, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-33977MEDIUM Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versi | Jun 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-27489MEDIUM Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files uploaded by users which could potentially contain JavaScript c | Mar 29, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-32686MEDIUM Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versi | May 27, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-30544MEDIUM Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This pa | Apr 24, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kiwitcms.
Media articles that mention a CVE ID that affects a product developed by Kiwitcms — matched by CVE ID, not by vendor name.