Ckan
Vendor:
First CVE: Dec 1, 2021 · Active for 4 years
14
Total CVEs
More Total CVEs than 92% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ckan over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2021
4 years ago
Most Recent CVE
May 13, 2026
76 days ago
CVE Severity & Scoring
Ckan14 CVEs
50%
29%
21%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low5 (35.7%)
High0 (0.0%)
None9 (64.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42031CRITICAL CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers | May 13, 2026 | 9.8 | 49 | NO | YES |
CVE-2026-42032CRITICAL CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers | May 13, 2026 | 9.1 | 31 | NO | NO |
CVE-2023-32321CRITICAL CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution | May 26, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-43685HIGH CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account includi | Nov 22, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-41132HIGH CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server may be spoofed with any certifi | May 13, 2026 | 7.4 | 27 | NO | NO |
CVE-2023-32696HIGH CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalent to www-data) owned code and c | May 30, 2023 | 8.8 | 26 | NO | NO |
CVE-2026-41255MEDIUM CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tokens or unauthenticated requests | May 13, 2026 | 6.1 | 24 | NO | NO |
CVE-2023-22746HIGH CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating a new container based on one of the Docker images listed below, the same | Feb 3, 2023 | 7.5 | 24 | NO | NO |
CVE-2024-43371MEDIUM CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext | Aug 21, 2024 | 6.5 | 19 | NO | NO |
CVE-2021-25967MEDIUM In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store mal | Dec 1, 2021 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Ckan
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.10.0 | 2 | 9.3 | 1.2% | 0 | 0 |