VulnSea

dspace has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 5.5 (medium).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.5
Publish → KEV
Last 90 days
4 prev 0

Weakness classes

Products

  • org.dspace:dspace-api 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

dspace vulnerabilities

CVEs affecting dspace, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-49832High· 8.0
2w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible …

Twilightdspace · org.dspace:dspace-apiEPSS 0.54%via NVD
CVE-2026-49831Medium· 5.5
2w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r param…

Sunlitdspace · org.dspace:dspace-apiEPSS 0.35%via NVD
CVE-2026-49830Medium· 4.4
2w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the …

Sunlitdspace · org.dspace:dspace-apiEPSS 0.41%via NVD
CVE-2026-49833Medium· 5.5
2w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, and 10-rc1 to before 10.0, a path traversal vulnerability is possible…

Sunlitdspace · org.dspace:dspace-apiEPSS 0.27%via NVD
dspace vulnerabilities (CVEs) · VulnSea