Konga Project develops a Kong API Gateway administration interface; its modest vulnerability footprint centers on the Konga product and reflects access-control and authorization-handling weaknesses typical of web-facing management tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Konga Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42192HIGH Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation. | May 4, 2022 | 8.8 | 44 | NO | YES |
CVE-2023-26987MEDIUM An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request. | May 1, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Konga Project.
Media articles that mention a CVE ID that affects a product developed by Konga Project — matched by CVE ID, not by vendor name.