VulnSea

ckan has 13 CVEs on record between 2023 and 2026. The busiest recent month was April 2026 with 4. The median CVSS is 6.1 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
0 prev 4

Products

  • ckan 13
13
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

ckan vulnerabilities

CVEs affecting ckan, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-42032Medium
4mo ago

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`

Sunlitckan · ckanEPSS 0.37%via OSV
CVE-2026-41132Medium
4mo ago

CKAN has no certificate validation on STMP connection

CKAN has no certificate validation on STMP connection

Sunlitckan · ckanEPSS 0.19%via OSV
CVE-2026-41255Medium· 6.1
4mo ago

CKAN has CSRF exemption primed by anonymous requests

CKAN has CSRF exemption primed by anonymous requests

Sunlitckan · ckanEPSS 0.12%via OSV
CVE-2026-42031HighPoC
4mo ago

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

Midnightckan · ckanEPSS 1.8%via OSV
CVE-2025-54384Medium· 6.3
10mo ago

CKAN vulnerable to stored XSS in resource description

CKAN vulnerable to stored XSS in resource description

Sunlitckan · ckanEPSS 0.21%via OSV
CVE-2025-64100Medium· 6.1
10mo ago

CKAN vulnerable to fixed session IDs

CKAN vulnerable to fixed session IDs

Sunlitckan · ckanEPSS 0.28%via OSV
CVE-2025-24372High· 7.3
1y ago

CKAN has an XSS vector in user uploaded images in group/org and user profiles

CKAN has an XSS vector in user uploaded images in group/org and user profiles

Twilightckan · ckanEPSS 0.46%via OSV
CVE-2024-41675Medium· 6.8
2y ago

CKAN has Cross-site Scripting vector in the Datatables view plugin

CKAN has Cross-site Scripting vector in the Datatables view plugin

Sunlitckan · ckanEPSS 0.40%via OSV
CVE-2024-43371Medium· 4.5
2y ago

Potential access to sensitive URLs via CKAN extensions (SSRF)

Potential access to sensitive URLs via CKAN extensions (SSRF)

Sunlitckan · ckanEPSS 0.37%via OSV
CVE-2024-41674Medium· 5.3
2y ago

CKAN may leak Solr credentials via error message in package_search action

CKAN may leak Solr credentials via error message in package_search action

Sunlitckan · ckanEPSS 0.38%via OSV
CVE-2024-27097Medium· 4.3
2y ago

Potential log injection in reset user endpoint in CKAN

Potential log injection in reset user endpoint in CKAN

Sunlitckan · ckanEPSS 0.44%via OSV
CVE-2023-50248Medium· 4.5
2y ago

Out of memory error when submitting the dataset form with a specially-crafted field

Out of memory error when submitting the dataset form with a specially-crafted field

Sunlitckan · ckanEPSS 0.58%via OSV
CVE-2023-32321Critical· 9.8
3y ago

Ckan remote code execution and private information access via crafted resource ids

Ckan remote code execution and private information access via crafted resource ids

Midnightckan · ckanEPSS 1.7%via OSV
ckan vulnerabilities (CVEs) · VulnSea