Withknown develops a personal publishing and social-networking platform centered on its flagship Known product, a modestly represented vulnerability footprint that skews toward serious severity outcomes despite its niche presence. The recurring exposure reflects the platform's web-facing architecture and spans application-layer weakness classes including cross-site scripting, authorization bypass, sensitive-information disclosure, injection, and OS command injection—issues endemic to user-input handling and privilege management in content-management systems. Defenders deploying this platform should prioritize input-validation and access-control hardening; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Withknown over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26273CRITICAL Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset to | Feb 13, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-28508HIGH Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivi | Mar 6, 2026 | 8.6 | 25 | NO | NO |
CVE-2026-28507HIGH Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and template path traversal. This issue h | Mar 6, 2026 | 7.2 | 23 | NO | NO |
CVE-2022-33011HIGH Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack. | Jul 8, 2022 | 8.8 | 22 | NO | NO |
CVE-2022-32115MEDIUM An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file. | Jul 8, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-31290MEDIUM A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into th | Jul 8, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-30852MEDIUM Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR). | Jul 8, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Withknown.
Media articles that mention a CVE ID that affects a product developed by Withknown — matched by CVE ID, not by vendor name.