Thinkst
Thinkst Canarytokens: vulnerabilidades y CVE
Thinkst Canarytokens tiene 11 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13140 | Baja (1.1) | 0.29% | — | 24 jun 2026 | Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Canarytokens: from Docker tag… |
| CVE-2026-12888 | Baja (2) | 0.44% | — | 22 jun 2026 | An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content… |
| CVE-2026-11859 | Baja (2) | 0.26% | — | 10 jun 2026 | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue… |
| CVE-2026-10729 | Baja (1.2) | 0.20% | — | 3 jun 2026 | An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting… |
| CVE-2026-28355 | Baja (1.3) | 0.45% | — | 27 feb 2026 | Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Scripting vulnerability in the "PWA" Canarytoken, whereby the Canarytoken's creator can attack themselves… |
| CVE-2024-41664 | Media (5.4) | 0.38% | — | 23 jul 2024 | Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook alert feature. When a Canarytoken is created, users choose to receive… |
| CVE-2024-41663 | Baja (3.5) | 0.35% | — | 23 jul 2024 | Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can attack themselves. The creator of… |
| CVE-2024-28111 | Media (6.5) | 0.63% | — | 6 mar 2024 | Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection… |
| CVE-2023-22475 | Media (6.1) | 0.52% | — | 6 ene 2023 | Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens prior to sha-fb61290. An… |
| CVE-2022-31113 | Media (6.1) | 0.58% | — | 1 jul 2022 | Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens. This permits an attacker who… |
| CVE-2019-9768 | Alta (7.5) | 12% | — | 14 mar 2019 | Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token. |