SurfSense vulnerabilities
CVEs whose affected-version data names the SurfSense package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-102245High· 7.3A weakness has been identified in MODSetter SurfSense up to 2.0.3
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipul…
CVE-2026-102244Medium· 4.3A security flaw has been discovered in MODSetter SurfSense up to 0.0.36
A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation result…
CVE-2026-102243High· 7.4A vulnerability was identified in MODSetter SurfSense up to 2.0.3
A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to comma…