Okfn maintains CKAN, a widely deployed open-source data management and publishing platform used by government agencies and organizations to catalog and share public datasets, presenting a prominent attack surface despite a narrow product focus. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, with recurring exposure centered on web-layer input handling including cross-site scripting, cross-site request forgery, and certificate validation issues that reflect CKAN's role as an internet-facing data portal. Defenders should treat CKAN instances—particularly those exposed to untrusted users or handling sensitive metadata—as a patching priority; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Okfn over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42031CRITICAL CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers | May 13, 2026 | 9.8 | 49 | NO | YES |
CVE-2026-42032CRITICAL CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers | May 13, 2026 | 9.1 | 31 | NO | NO |
CVE-2023-32321CRITICAL CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution | May 26, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-43685HIGH CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account includi | Nov 22, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-41132HIGH CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server may be spoofed with any certifi | May 13, 2026 | 7.4 | 27 | NO | NO |
CVE-2023-32696HIGH CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalent to www-data) owned code and c | May 30, 2023 | 8.8 | 26 | NO | NO |
CVE-2026-41255MEDIUM CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tokens or unauthenticated requests | May 13, 2026 | 6.1 | 24 | NO | NO |
CVE-2023-22746HIGH CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating a new container based on one of the Docker images listed below, the same | Feb 3, 2023 | 7.5 | 24 | NO | NO |
CVE-2024-43371MEDIUM CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext | Aug 21, 2024 | 6.5 | 19 | NO | NO |
CVE-2021-25967MEDIUM In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store mal | Dec 1, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Okfn.
Media articles that mention a CVE ID that affects a product developed by Okfn — matched by CVE ID, not by vendor name.