Woodpecker CI is a continuous integration and automation platform with a narrow, focused product footprint that has found adoption in software development pipelines despite modest overall disclosure volume. The vendor's vulnerability surface reflects its role as a build and deployment orchestrator; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Woodpecker Ci over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58370HIGH Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author | Jun 30, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-58369MEDIUM Woodpecker before 3.15.0 registers the /api/orgs/lookup/*org_full_name endpoint without authentication middleware, and the LookupOrg handler unconditionally dereferences the sessio | Jun 30, 2026 | 5.3 | 27 | NO | NO |
CVE-2024-41121HIGH Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious workflows: 1. Those workflow | Jul 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-41122HIGH Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious workflows: 1. Those workflow | Jul 19, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-40034HIGH Woodpecker is a community fork of the Drone CI system. In affected versions an attacker can post malformed webhook data witch lead to an update of the repository data that can e.g. | Aug 16, 2023 | 8.1 | 25 | NO | NO |
CVE-2022-29947MEDIUM Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping. | Apr 29, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Woodpecker Ci.
Media articles that mention a CVE ID that affects a product developed by Woodpecker Ci — matched by CVE ID, not by vendor name.