MODSetter has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.3 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
MODSetter vulnerabilities
CVEs affecting MODSetter, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-102245High· 7.3A weakness has been identified in MODSetter SurfSense up to 2.0.3
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipul…
CVE-2026-102244Medium· 4.3A security flaw has been discovered in MODSetter SurfSense up to 0.0.36
A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation result…
CVE-2026-102243High· 7.4A vulnerability was identified in MODSetter SurfSense up to 2.0.3
A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to comma…