Qanything is a focused document-processing and knowledge-retrieval product that exhibits a narrow but recurring vulnerability pattern centered on application-layer input handling and session security. The observed weakness classes—SQL injection and cross-site request forgery—reflect typical risks in web-accessible systems that parse user input and manage user sessions; current severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qanything over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7099CRITICAL netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected fu | Oct 13, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-25722CRITICAL qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection. | Feb 11, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-8026HIGH A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers | Mar 20, 2025 | 8.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qanything.
Media articles that mention a CVE ID that affects a product developed by Qanything — matched by CVE ID, not by vendor name.