Omeka is a focused digital collections and exhibition platform whose vulnerability footprint concentrates in its core Omeka and Omeka S products. The recurring exposure pattern reflects application-layer input and access-control weaknesses—including cross-site scripting, cross-site request forgery, server-side request forgery, and improper authorization—that are characteristic of web-based content-management and data-publishing systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Omeka over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5100MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) add a n | Jul 25, 2014 | 6.8 | 34 | NO | YES |
CVE-2023-4159HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3. | Aug 4, 2023 | 8.8 | 25 | NO | NO |
CVE-2021-26799MEDIUM Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject arbitrary web script or HTML. | Jul 23, 2021 | 6.1 | 22 | NO | NO |
CVE-2023-4560MEDIUM Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4. | Aug 28, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-4158MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3. | Aug 4, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-4157MEDIUM CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in GitHub repository omeka/omeka-s prior to version 4.0.3.
| Aug 4, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-3982MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.2. | Jul 27, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-3981MEDIUM Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2. | Jul 27, 2023 | 4.9 | 18 | NO | NO |
CVE-2018-13423MEDIUM admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag. | Jul 7, 2018 | 6.1 | 18 | NO | NO |
CVE-2023-4561MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4. | Aug 28, 2023 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Omeka.
Media articles that mention a CVE ID that affects a product developed by Omeka — matched by CVE ID, not by vendor name.