scancodeio vulnerabilities
CVEs whose affected-version data names the scancodeio package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2023-40024Medium· 6.1Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
▾ Sunlitscancodeio · scancodeioEPSS 0.51%via OSV
CVE-2023-39523Medium· 6.8ScanCode.io command injection in docker image fetch process
ScanCode.io command injection in docker image fetch process
▾ Sunlitscancodeio · scancodeioEPSS 2.9%via OSV