ckan vulnerabilities
CVEs whose affected-version data names the ckan package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
13 CVEsRSS
CVE-2026-42032MediumCKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2026-41132MediumCKAN has no certificate validation on STMP connection
CKAN has no certificate validation on STMP connection
CVE-2026-41255Medium· 6.1CKAN has CSRF exemption primed by anonymous requests
CKAN has CSRF exemption primed by anonymous requests
CVE-2026-42031HighPoCCKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2025-54384Medium· 6.3CKAN vulnerable to stored XSS in resource description
CKAN vulnerable to stored XSS in resource description
CVE-2025-64100Medium· 6.1CKAN vulnerable to fixed session IDs
CKAN vulnerable to fixed session IDs
CVE-2025-24372High· 7.3CKAN has an XSS vector in user uploaded images in group/org and user profiles
CKAN has an XSS vector in user uploaded images in group/org and user profiles
CVE-2024-41675Medium· 6.8CKAN has Cross-site Scripting vector in the Datatables view plugin
CKAN has Cross-site Scripting vector in the Datatables view plugin
CVE-2024-43371Medium· 4.5Potential access to sensitive URLs via CKAN extensions (SSRF)
Potential access to sensitive URLs via CKAN extensions (SSRF)
CVE-2024-41674Medium· 5.3CKAN may leak Solr credentials via error message in package_search action
CKAN may leak Solr credentials via error message in package_search action
CVE-2024-27097Medium· 4.3Potential log injection in reset user endpoint in CKAN
Potential log injection in reset user endpoint in CKAN
CVE-2023-50248Medium· 4.5Out of memory error when submitting the dataset form with a specially-crafted field
Out of memory error when submitting the dataset form with a specially-crafted field
CVE-2023-32321Critical· 9.8Ckan remote code execution and private information access via crafted resource ids
Ckan remote code execution and private information access via crafted resource ids