Withknown
Withknown Known: vulnerabilidades y CVE
Withknown Known tiene 7 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses3
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-28508 | Crítica (9.2) | 0.72% | — | 6 mar 2026 | Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivially bypassed by any unauthenticated… |
| CVE-2026-28507 | Alta (8.6) | 0.92% | — | 6 mar 2026 | Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and template path traversal. This issue has been patched in version 1.6.4. |
| CVE-2026-26273 | Crítica (9.8) | 1.2% | — | 13 feb 2026 | Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden HTML input field on… |
| CVE-2022-33011 | Alta (8.8) | 1.5% | — | 8 jul 2022 | Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack. |
| CVE-2022-32115 | Media (6.1) | 1.4% | — | 8 jul 2022 | An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file. |
| CVE-2022-31290 | Media (5.4) | 0.86% | — | 8 jul 2022 | A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field. |
| CVE-2022-30852 | Media (4.3) | 0.95% | — | 8 jul 2022 | Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR). |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.