Ushahidi develops a crisis-mapping and crowdsourced information platform intended for humanitarian response and social accountability in conflict and disaster contexts, with vulnerabilities concentrating in a focused product line. The recurring weakness classes reflect common web-application challenges: SQL injection, authentication bypasses, cross-site scripting, and sensitive information exposure, indicating input-handling and session-management demands typical of data-aggregation platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ushahidi over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5618CRITICAL Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens. | Feb 4, 2020 | 9.8 | 29 | NO | NO |
CVE-2012-3471HIGH Multiple SQL injection vulnerabilities in the edit functions in (1) application/controllers/admin/reports.php and (2) application/controllers/members/reports.php in the Ushahidi Pl | Aug 12, 2012 | 7.5 | 24 | NO | NO |
CVE-2012-3475HIGH The installer in the Ushahidi Platform before 2.5 omits certain calls to the exit function, which allows remote attackers to obtain administrative privileges via unspecified vector | Aug 12, 2012 | 7.5 | 22 | NO | NO |
CVE-2012-3470HIGH Multiple SQL injection vulnerabilities in application/libraries/api/MY_Countries_Api_Object.php in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL | Aug 12, 2012 | 7.5 | 22 | NO | NO |
CVE-2012-3469HIGH Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the messages admin fu | Aug 12, 2012 | 7.5 | 22 | NO | NO |
CVE-2012-3473MEDIUM The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate | Aug 12, 2012 | 6.4 | 21 | NO | NO |
CVE-2012-3472MEDIUM The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows remote attackers to list, delet | Aug 12, 2012 | 6.4 | 21 | NO | NO |
CVE-2012-3468HIGH Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the verify function i | Aug 12, 2012 | 7.5 | 21 | NO | NO |
CVE-2013-2025MEDIUM Cross-site scripting (XSS) vulnerability in Ushahidi Platform 2.5.x through 2.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 25, 2014 | 4.3 | 19 | NO | NO |
CVE-2012-3474MEDIUM The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mai | Aug 12, 2012 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ushahidi.
Media articles that mention a CVE ID that affects a product developed by Ushahidi — matched by CVE ID, not by vendor name.