kiwitcms has 12 CVEs on record between 2022 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.8 (medium). None have a confirmed exploitation report. Most affected products: kiwitcms (9), Kiwi (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2023-33977High· 8.1kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload57CVE-2023-36809High· 8.1Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox45CVE-2023-30613High· 7.7Unrestricted file upload in kiwi TCMS43CVE-2023-27489High· 7.6Kiwi TCMS Stored Cross-site Scripting via SVG file42CVE-2023-25171High· 7.5Denial of service vulnerability on Password reset page41
kiwitcms vulnerabilities
CVEs affecting kiwitcms, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-49292Low· 0.0Kiwi TCMS is an open source test management system
Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migra…
CVE-2026-55630Low· 0.0Kiwi TCMS is an open source test management system
Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Officia…
CVE-2026-54724Medium· 6.1Kiwi TCMS is an open source test management system
Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redire…
CVE-2023-36809High· 8.1Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
CVE-2023-33977High· 8.1PoCkiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
kiwitcms vulnerable to stored cross-site scripting via unrestricted file upload
CVE-2023-32686Medium· 5.4kiwitcms vulnerable to stored XSS via unrestricted files upload
kiwitcms vulnerable to stored XSS via unrestricted files upload
CVE-2023-30613High· 7.7Unrestricted file upload in kiwi TCMS
Unrestricted file upload in kiwi TCMS
CVE-2023-30544None· 0.0kiwi TCMS has possibility for user to update email address to unverified one
kiwi TCMS has possibility for user to update email address to unverified one
CVE-2023-27489High· 7.6Kiwi TCMS Stored Cross-site Scripting via SVG file
Kiwi TCMS Stored Cross-site Scripting via SVG file
CVE-2023-25171High· 7.5Denial of service vulnerability on Password reset page
Denial of service vulnerability on Password reset page
CVE-2023-25156High· 7.5No protection against brute-force attacks on login page
No protection against brute-force attacks on login page
CVE-2022-4105Medium· 5.4Cross-site Scripting in kiwitcms
Cross-site Scripting in kiwitcms