Komoot is an outdoor navigation and trip-planning application whose vulnerability disclosures center on the mobile and web product. The recurring weakness classes—including exposure of sensitive information and private personal data to unauthorized actors, and improper certificate validation—reflect the application's handling of user location data, authentication, and network communication. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Komoot over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21823HIGH An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted series of network requests can l | Aug 20, 2021 | 7.5 | 24 | NO | NO |
CVE-2017-14709HIGH The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 certificates from SSL servers, whic | Jul 12, 2018 | 7.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Komoot.
Media articles that mention a CVE ID that affects a product developed by Komoot — matched by CVE ID, not by vendor name.