Kiwi Tcms
Vendor:
First CVE: Nov 21, 2022 · Active for 3 years
11
Total CVEs
More Total CVEs than 90% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Kiwi Tcms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2022
3 years ago
Most Recent CVE
Jul 5, 2023
1,119 days ago
CVE Severity & Scoring
Kiwi Tcms11 CVEs
64%
18%
18%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low8 (72.7%)
High0 (0.0%)
None3 (27.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30613CRITICAL Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control ove | Apr 24, 2023 | 9.0 | 29 | NO | NO |
CVE-2023-25156CRITICAL Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. | Feb 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-22451HIGH Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would | Jan 2, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-30628HIGH Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior,
the `changelog.yml` workflow is vulnerable to command | Apr 24, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-25171MEDIUM Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Passw | Feb 15, 2023 | 5.9 | 20 | NO | NO |
CVE-2023-36809MEDIUM Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which | Jul 5, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-33977MEDIUM Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versi | Jun 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-27489MEDIUM Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files uploaded by users which could potentially contain JavaScript c | Mar 29, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-32686MEDIUM Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versi | May 27, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-30544MEDIUM Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This pa | Apr 24, 2023 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Kiwi Tcms
Top CWEs
Versions
No cataloged versions.