Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

iris-web — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in iris-web, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumerations (CWE) and associated vulnerabilities affecting the iris-web product developed by its vendor. It serves as a centralized resource for security professionals and developers to analyze the security posture of this specific web application platform without navigating multiple disparate sources. The collection covers a wide spectrum of vulnerability types, including injection flaws, broken access control, security misconfigurations, and cross-site scripting issues that have been reported since the product's inception through the present day. By compiling data from various public advisories, security bulletins, and community reports, the page ensures a chronological and contextual view of all known security issues. Users can leverage this information to track vendor advisories and understand how the provider responds to critical security incidents over time. Additionally, the aggregated data allows for a deeper understanding of specific weakness classes prevalent in the iris-web ecosystem, highlighting recurring patterns or architectural weaknesses. Readers can also look up the product's vulnerability history to assess risk trends, evaluate the effectiveness of past patches, and plan proactive security audits. This structured approach facilitates informed decision-making for risk management and compliance activities, ensuring that stakeholders have a clear, factual basis for securing their deployments against known threats associated with this software.

Vendor: dfir-iris

CVE ID Title CVSS Severity Published
CVE-2026-16970 DFIR-IRIS Insufficient Logout Implementation CWE-613 4.2 Medium 2026-07-30
CVE-2026-18362 DFIR-IRIS Missing Brute Force Protection in User Authentication CWE-770 5.9 Medium 2026-07-30
CVE-2026-16971 DFIR-IRIS Missing Brute Force Protection in OTP Validation CWE-770 5.9 Medium 2026-07-30
CVE-2026-18361 DFIR-IRIS Stored XSS in Datastore Upload CWE-79 7.6 High 2026-07-30
CVE-2026-18360 DFIR-IRIS Stored XSS in Custom Attributes CWE-79 7.6 High 2026-07-30
CVE-2026-16969 DFIR-IRIS Stored XSS in Assets CWE-79 7.6 High 2026-07-30
CVE-2026-42547 IRIS Alerts Can be Falsely Attributed to Customers CWE-863 5.4 Medium 2026-06-04
CVE-2026-42543 IRIS has a Cross-Site Request Forgery (CSRF) issue CWE-650 4.3 Medium 2026-06-04
CVE-2026-42540 IRIS has a Mass Assignment issue CWE-915 4.3 Medium 2026-06-04
CVE-2026-42539 IRIS has an Excessive Data Exposure issue CWE-201 6.5 Medium 2026-06-04
CVE-2026-42538 IRIS has an Insecure File Upload CWE-434 6.3 Medium 2026-06-04
CVE-2026-42329 Iris has an Open Redirect issue CWE-602 4.7 Medium 2026-06-04
CVE-2026-41522 Iris has an Improper Authorization issue CWE-285 - - 2026-06-04
CVE-2026-22783 Iris Allows Arbitrary File Deletion via Mass Assignment in Datastore File Management CWE-434 9.6 Critical 2026-01-12
CVE-2024-25624 iris-web vulnerable to Server Side Template Injection in reports CWE-1336 6.8 Medium 2024-04-25
CVE-2024-25640 Improper Neutralization of Alternate XSS Syntax in iris-web CWE-87 4.6 Medium 2024-02-19
CVE-2023-50712 Improper Neutralization of Alternate XSS Syntax in iris-web CWE-87 4.6 Medium 2023-12-22
CVE-2023-30615 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in iris-web CWE-80 6.3 Medium 2023-05-25

All 18 known CVE vulnerabilities affecting iris-web with full Chinese analysis, references, and POCs where available.