wsgidav vulnerabilities
CVEs whose affected-version data names the wsgidav package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55509HighWsgiDAV MySQL provider has a blind SQL injection
WsgiDAV MySQL provider has a blind SQL injection
▾ Twilightwsgidav · wsgidavEPSS 0.40%via OSV
CVE-2026-48099High· 7.1WsgiDAV is a generic and extendable WebDAV server based on WSGI
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path lay…
▾ Twilightwsgidav · wsgidavEPSS 0.33%via NVD