Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Kiteworks — Vulnerabilities & Security Advisories 85

Browse all 85 CVE security advisories affecting Kiteworks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kiteworks provides a secure file transfer and content collaboration platform for enterprises handling sensitive data. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation failures and access control weaknesses. The platform has faced multiple security incidents, including a 2023 breach exposing customer data due to an unpatched vulnerability. With 15 CVEs recorded, Kiteworks has demonstrated recurring issues in secure coding practices, particularly in web application components and authentication mechanisms. Organizations implementing Kiteworks should prioritize timely patching and harden configurations against common attack vectors targeting enterprise file sharing systems.

CVE ID Title CVSS Severity Published
CVE-2026-102105 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102106 Kiteworks Email Protection Gateway improper authentication — Email Protection Gateway CWE-287 9.1 Critical 2026-09-30
CVE-2026-102107 Kiteworks Core user impersonation in a file-request feature — Core CWE-639 4.6 Medium 2026-09-30
CVE-2026-102108 Kiteworks Email Protection Gateway deserialization of untrusted data — Email Protection Gateway CWE-502 7.2 High 2026-09-30
CVE-2026-102109 Kiteworks Secure Data Forms SQL injection — Secure Data Forms CWE-89 7.1 High 2026-09-30
CVE-2026-102110 Missing authentication on a Kiteworks appliance setup function — Core CWE-306 5.9 Medium 2026-09-30
CVE-2026-102111 Kiteworks Core Improper Validation of Specified Quantity in Input — Core CWE-1284 4.9 Medium 2026-09-30
CVE-2026-102112 Kiteworks Core Local Privilege Escalation — Core CWE-78 7.8 High 2026-09-30
CVE-2026-102113 Kiteworks Core Local Privilege Escalation — Core CWE-59 7.8 High 2026-09-30
CVE-2026-102114 Kiteworks Core OS Command Injection — Core CWE-78 7.2 High 2026-09-30
CVE-2026-102115 Kiteworks Core Authentication Bypass in the Password Reset Workflow — Core CWE-640 9.8 Critical 2026-09-30
CVE-2026-102116 Kiteworks Email Protection Gateway Path Traversal — Email Protection Gateway CWE-22 7.2 High 2026-09-30
CVE-2026-102117 Kiteworks Core Remote Code Execution — Core CWE-807 7.2 High 2026-09-30
CVE-2026-102118 Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation — Core CWE-59 7.8 High 2026-09-30
CVE-2026-102119 Kiteworks Email Protection Gateway Path Traversal — Email Protection Gateway CWE-22 7.2 High 2026-09-30
CVE-2026-102120 Kiteworks Core OS Command Injection — Core CWE-78 8.8 High 2026-09-30
CVE-2026-102121 Kiteworks Secure Data Forms Exposure of Sensitive Information to an Unauthorized Actor — Secure Data Forms CWE-200 8.6 High 2026-09-30
CVE-2026-102104 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102122 Kiteworks Core Incorrect Authorization — Core CWE-863 4.3 Medium 2026-09-30
CVE-2026-102123 Kiteworks Core Path Traversal — Core CWE-22 7.4 High 2026-09-30
CVE-2026-102103 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102124 Kiteworks Core Missing Authentication for Critical Function — Core CWE-306 6.5 Medium 2026-09-30
CVE-2026-102125 Kiteworks Core Sandbox Escape — Core CWE-653 8.8 High 2026-09-30
CVE-2026-102126 Kiteworks Core Stored Cross-site Scripting (XSS) — Core CWE-79 8.1 High 2026-09-30
CVE-2026-102127 Kiteworks Email Protection Gateway Improper Restriction of XML External Entity Reference — Email Protection Gateway CWE-611 7.0 High 2026-09-30
CVE-2026-102128 Kiteworks Email Protection Gateway Improper Authentication — Email Protection Gateway CWE-287 7.5 High 2026-09-30
CVE-2026-102129 Kiteworks Core Incorrect Privilege Assignment — Core CWE-266 7.2 High 2026-09-30
CVE-2026-102130 Kiteworks Email Protection Gateway Remote Code Execution — Email Protection Gateway CWE-94 7.2 High 2026-09-30
CVE-2026-102131 Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity — Email Protection Gateway CWE-94 7.2 High 2026-09-30
CVE-2026-102132 Kiteworks Core Privilege Escalation through Improper Access Control — Core CWE-284 7.2 High 2026-09-30

This page lists every published CVE security advisory associated with Kiteworks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.