Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Kiteworks — Vulnerabilities & Security Advisories 85

Browse all 85 CVE security advisories affecting Kiteworks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kiteworks provides a secure file transfer and content collaboration platform for enterprises handling sensitive data. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation failures and access control weaknesses. The platform has faced multiple security incidents, including a 2023 breach exposing customer data due to an unpatched vulnerability. With 15 CVEs recorded, Kiteworks has demonstrated recurring issues in secure coding practices, particularly in web application components and authentication mechanisms. Organizations implementing Kiteworks should prioritize timely patching and harden configurations against common attack vectors targeting enterprise file sharing systems.

Found 22 results / 85 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-102105 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102106 Kiteworks Email Protection Gateway improper authentication — Email Protection Gateway CWE-287 9.1 Critical 2026-09-30
CVE-2026-102108 Kiteworks Email Protection Gateway deserialization of untrusted data — Email Protection Gateway CWE-502 7.2 High 2026-09-30
CVE-2026-102116 Kiteworks Email Protection Gateway Path Traversal — Email Protection Gateway CWE-22 7.2 High 2026-09-30
CVE-2026-102119 Kiteworks Email Protection Gateway Path Traversal — Email Protection Gateway CWE-22 7.2 High 2026-09-30
CVE-2026-102104 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102103 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102127 Kiteworks Email Protection Gateway Improper Restriction of XML External Entity Reference — Email Protection Gateway CWE-611 7.0 High 2026-09-30
CVE-2026-102128 Kiteworks Email Protection Gateway Improper Authentication — Email Protection Gateway CWE-287 7.5 High 2026-09-30
CVE-2026-102130 Kiteworks Email Protection Gateway Remote Code Execution — Email Protection Gateway CWE-94 7.2 High 2026-09-30
CVE-2026-102131 Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity — Email Protection Gateway CWE-94 7.2 High 2026-09-30
CVE-2026-102102 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102135 Kiteworks Email Protection Gateway Deserialization of Untrusted Data — Email Protection Gateway CWE-502 6.6 Medium 2026-09-30
CVE-2026-102139 Kiteworks Email Protection Gateway Incorrect Authorization — Email Protection Gateway CWE-639 6.5 Medium 2026-09-30
CVE-2026-102143 Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous Type — Email Protection Gateway CWE-306 7.5 High 2026-09-30
CVE-2026-102144 Kiteworks Email Protection Gateway Uncontrolled Resource Consumption — Email Protection Gateway CWE-306 5.3 Medium 2026-09-30
CVE-2026-102149 Kiteworks Email Protection Gateway Improper Access Control — Email Protection Gateway CWE-306 9.4 Critical 2026-09-30
CVE-2026-102146 Kiteworks Email Protection Gateway Arbitrary File Write through Server-Side Template Injection — Email Protection Gateway CWE-73 6.5 Medium 2026-09-30
CVE-2026-102097 Kiteworks Email Protection Gateway remote code execution — Email Protection Gateway CWE-22 7.2 High 2026-09-30
CVE-2026-102095 Kiteworks Email Protection Gateway server-side request forgery — Email Protection Gateway CWE-918 9.1 Critical 2026-09-30
CVE-2026-102094 Kiteworks Email Protection Gateway unsafe reflection — Email Protection Gateway CWE-470 7.2 High 2026-09-30
CVE-2026-102089 Kiteworks Email Protection Gateway path traversal — Email Protection Gateway CWE-22 7.2 High 2026-09-30

This page lists every published CVE security advisory associated with Kiteworks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.