VulnSea

secure_data_forms vulnerabilities

CVEs whose affected-version data names the secure_data_forms package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-102150High· 7.2
today

A function in the Kiteworks Advanced Forms component was reachable without authentication

A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did n…

▾ TwilightKiteworks · Secure Data Formsvia NVD
CVE-2026-102121High· 8.6
today

A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required

A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the w…

▾ TwilightKiteworks · Secure Data Formsvia NVD
CVE-2026-102109High· 7.1
today

A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization

A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could…

▾ TwilightKiteworks · Secure Data Formsvia NVD
CVE-2026-102091High· 7.5
today

Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses

Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. …

▾ TwilightKiteworks · Secure Data Formsvia NVD
secure_data_forms vulnerabilities (CVEs) · VulnSea