Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

core — Vulnerabilities & Security Advisories 137

All 137 CVE vulnerabilities found in core, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories and vulnerability records for the product core. It collects entries spanning multiple years, covering various weakness classes including buffer overflows, memory corruption, and access control flaws. Readers can track the vendor's published advisories, understand the evolution of specific weakness categories, and review the product's complete vulnerability history to identify recurring patterns. The dataset includes both confirmed and unpatched issues, enabling users to assess the overall risk profile and remediation status over time. By correlating vulnerability reports with patch releases, the page helps teams prioritize updates and verify that known defects have been addressed in the latest build.

Vendor: Drupal

CVE ID Title CVSS Severity Published
CVE-2026-102107 Kiteworks Core user impersonation in a file-request feature CWE-639 4.6 Medium 2026-09-30
CVE-2026-102110 Missing authentication on a Kiteworks appliance setup function CWE-306 5.9 Medium 2026-09-30
CVE-2026-102111 Kiteworks Core Improper Validation of Specified Quantity in Input CWE-1284 4.9 Medium 2026-09-30
CVE-2026-102112 Kiteworks Core Local Privilege Escalation CWE-78 7.8 High 2026-09-30
CVE-2026-102113 Kiteworks Core Local Privilege Escalation CWE-59 7.8 High 2026-09-30
CVE-2026-102114 Kiteworks Core OS Command Injection CWE-78 7.2 High 2026-09-30
CVE-2026-102115 Kiteworks Core Authentication Bypass in the Password Reset Workflow CWE-640 9.8 Critical 2026-09-30
CVE-2026-102117 Kiteworks Core Remote Code Execution CWE-807 7.2 High 2026-09-30
CVE-2026-102118 Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation CWE-59 7.8 High 2026-09-30
CVE-2026-102120 Kiteworks Core OS Command Injection CWE-78 8.8 High 2026-09-30
CVE-2026-102122 Kiteworks Core Incorrect Authorization CWE-863 4.3 Medium 2026-09-30
CVE-2026-102123 Kiteworks Core Path Traversal CWE-22 7.4 High 2026-09-30
CVE-2026-102124 Kiteworks Core Missing Authentication for Critical Function CWE-306 6.5 Medium 2026-09-30
CVE-2026-102125 Kiteworks Core Sandbox Escape CWE-653 8.8 High 2026-09-30
CVE-2026-102126 Kiteworks Core Stored Cross-site Scripting (XSS) CWE-79 8.1 High 2026-09-30
CVE-2026-102129 Kiteworks Core Incorrect Privilege Assignment CWE-266 7.2 High 2026-09-30
CVE-2026-102132 Kiteworks Core Privilege Escalation through Improper Access Control CWE-284 7.2 High 2026-09-30
CVE-2026-102133 Kiteworks Core Arbitrary File Write through Command Injection CWE-77 6.6 Medium 2026-09-30
CVE-2026-102134 Kiteworks Core Unprotected Alternate Channel CWE-420 5.4 Medium 2026-09-30
CVE-2026-102136 Kiteworks Core Command Execution through Configuration Injection CWE-93 6.3 Medium 2026-09-30
CVE-2026-102137 Kiteworks Core Unrestricted Upload of File with Dangerous Type CWE-434 4.1 Medium 2026-09-30
CVE-2026-102138 Kiteworks Core Server-Side Request Forgery (SSRF) CWE-918 3.3 Low 2026-09-30
CVE-2026-102101 Kiteworks Core deserialization of untrusted data CWE-502 8.1 High 2026-09-30
CVE-2026-102140 Kiteworks Core Insufficient Verification of Data Authenticity CWE-345 4.9 Medium 2026-09-30
CVE-2026-102141 Kiteworks Core Privilege Escalation through External Control of File Name or Path CWE-73 6.7 Medium 2026-09-30
CVE-2026-102142 Kiteworks Core Remote Code Execution through Server-Side Template Injection CWE-1336 7.2 High 2026-09-30
CVE-2026-102100 Kiteworks Core stored XSS CWE-79 8.7 High 2026-09-30
CVE-2026-102147 Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) CWE-79 9.3 Critical 2026-09-30
CVE-2026-102145 Kiteworks Core Server-Side Request Forgery through CRLF Injection CWE-93 6.6 Medium 2026-09-30
CVE-2026-102096 Kiteworks Core OS command injection CWE-78 7.2 High 2026-09-30

All 137 known CVE vulnerabilities affecting core with full Chinese analysis, references, and POCs where available.