CVE-2024-41675Medium· 6.8▾ SunlitCKAN has Cross-site Scripting vector in the Datatables view plugin
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector.
Sites running CKAN >= 2.7.0 with the datatables_view plugin activated. This is a plugin included in CKAN core, that not activated by default but it is widely used to preview tabular data.
This vulnerability has been fixed in CKAN 2.10.5 and 2.11.0
Prevent importing of tabular files to the DataStore via DataPusher, XLoader,etc, at least those published from untrusted sources.
ckan >= 2.7.0, < 2.10.5Upgrade to a patched release:
ckan 2.10.5Connected by shared product, vendor, weakness, or advisory.
CVE-2023-32321Critical· 9.8Ckan remote code execution and private information access via crafted resource ids
CVE-2026-41132MediumCKAN has no certificate validation on STMP connection
CVE-2026-41255Medium· 6.1CKAN has CSRF exemption primed by anonymous requests
CVE-2026-42031HighCKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-42032MediumCKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2024-43371Medium· 4.5Potential access to sensitive URLs via CKAN extensions (SSRF)