Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Kiteworks — Vulnerabilities & Security Advisories 85

Browse all 85 CVE security advisories affecting Kiteworks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kiteworks provides a secure file transfer and content collaboration platform for enterprises handling sensitive data. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation failures and access control weaknesses. The platform has faced multiple security incidents, including a 2023 breach exposing customer data due to an unpatched vulnerability. With 15 CVEs recorded, Kiteworks has demonstrated recurring issues in secure coding practices, particularly in web application components and authentication mechanisms. Organizations implementing Kiteworks should prioritize timely patching and harden configurations against common attack vectors targeting enterprise file sharing systems.

CVE ID Title CVSS Severity Published
CVE-2026-102133 Kiteworks Core Arbitrary File Write through Command Injection — Core CWE-77 6.6 Medium 2026-09-30
CVE-2026-102102 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102134 Kiteworks Core Unprotected Alternate Channel — Core CWE-420 5.4 Medium 2026-09-30
CVE-2026-102135 Kiteworks Email Protection Gateway Deserialization of Untrusted Data — Email Protection Gateway CWE-502 6.6 Medium 2026-09-30
CVE-2026-102136 Kiteworks Core Command Execution through Configuration Injection — Core CWE-93 6.3 Medium 2026-09-30
CVE-2026-102137 Kiteworks Core Unrestricted Upload of File with Dangerous Type — Core CWE-434 4.1 Medium 2026-09-30
CVE-2026-102138 Kiteworks Core Server-Side Request Forgery (SSRF) — Core CWE-918 3.3 Low 2026-09-30
CVE-2026-102101 Kiteworks Core deserialization of untrusted data — Core CWE-502 8.1 High 2026-09-30
CVE-2026-102139 Kiteworks Email Protection Gateway Incorrect Authorization — Email Protection Gateway CWE-639 6.5 Medium 2026-09-30
CVE-2026-102140 Kiteworks Core Insufficient Verification of Data Authenticity — Core CWE-345 4.9 Medium 2026-09-30
CVE-2026-102141 Kiteworks Core Privilege Escalation through External Control of File Name or Path — Core CWE-73 6.7 Medium 2026-09-30
CVE-2026-102142 Kiteworks Core Remote Code Execution through Server-Side Template Injection — Core CWE-1336 7.2 High 2026-09-30
CVE-2026-102143 Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type — Email Protection Gateway CWE-306 7.5 High 2026-09-30
CVE-2026-102100 Kiteworks Core stored XSS — Core CWE-79 8.7 High 2026-09-30
CVE-2026-102144 Kiteworks Email Protection Gateway Uncontrolled Resource Consumption — Email Protection Gateway CWE-306 5.3 Medium 2026-09-30
CVE-2026-102150 Kiteworks Secure Data Forms Missing Authentication for Critical Function — Secure Data Forms CWE-306 7.2 High 2026-09-30
CVE-2026-102149 Kiteworks Email Protection Gateway Improper Access Control — Email Protection Gateway CWE-306 9.4 Critical 2026-09-30
CVE-2026-102147 Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) — Core CWE-79 9.3 Critical 2026-09-30
CVE-2026-102146 Kiteworks Email Protection Gateway Arbitrary File Write through Server-Side Template Injection — Email Protection Gateway CWE-73 6.5 Medium 2026-09-30
CVE-2026-102145 Kiteworks Core Server-Side Request Forgery through CRLF Injection — Core CWE-93 6.6 Medium 2026-09-30
CVE-2026-102097 Kiteworks Email Protection Gateway remote code execution — Email Protection Gateway CWE-22 7.2 High 2026-09-30
CVE-2026-102096 Kiteworks Core OS command injection — Core CWE-78 7.2 High 2026-09-30
CVE-2026-102099 Kiteworks Core arbitrary file write — Core CWE-22 7.2 High 2026-09-30
CVE-2026-102095 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102094 Kiteworks Email Protection Gateway unsafe reflection — Email Protection Gateway CWE-470 7.2 High 2026-09-30
CVE-2026-102093 Kiteworks Core improper privilege management — Core CWE-269 7.2 High 2026-09-30
CVE-2026-102092 Kiteworks Core stored XSS — Core CWE-79 8.7 High 2026-09-30
CVE-2026-102091 Kiteworks Secure Data Forms server-side request forgery — Secure Data Forms CWE-918 7.5 High 2026-09-30
CVE-2026-102090 Kiteworks Core content injection — Core CWE-601 4.3 Medium 2026-09-30
CVE-2026-102098 Kiteworks Core SQL Injection — Core CWE-89 7.2 High 2026-09-30

This page lists every published CVE security advisory associated with Kiteworks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.