Partkeepr is a niche open-source parts inventory and management application whose vulnerability footprint centers on web-layer input handling and data exposure, as evidenced by recurring weaknesses in cross-site scripting, sensitive information disclosure, and server-side request forgery. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Partkeepr over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22701MEDIUM PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local fi | Jan 10, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-39390MEDIUM Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter. | May 3, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-30899MEDIUM A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories. | Jun 8, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-22702MEDIUM PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an | Jan 10, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Partkeepr.
Media articles that mention a CVE ID that affects a product developed by Partkeepr — matched by CVE ID, not by vendor name.