Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

dfir-iris — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting dfir-iris. AI-powered Chinese analysis, POCs, and references for each vulnerability.

DFIR-IRIS is a digital forensics and incident response platform designed for comprehensive security investigations and threat hunting. Historically, it has been associated with vulnerabilities including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, with six CVEs documented to date. The platform's security characteristics focus on robust evidence collection and analysis capabilities, though specific major incidents remain undisclosed. Its core use case centers on enabling security teams to conduct thorough forensic examinations, detect advanced threats, and respond effectively to security breaches across complex IT environments.

Top products by dfir-iris: iris-web iris-evtx-module
CVE ID Title CVSS Severity Published
CVE-2026-92605 IRIS through 2.4.29 Unauthorized Comment Access via Object ID — iris-web CWE-639 6.5 Medium 2026-09-16
CVE-2026-16970 DFIR-IRIS Insufficient Logout Implementation — iris-web CWE-613 4.2 Medium 2026-07-30
CVE-2026-18362 DFIR-IRIS Missing Brute Force Protection in User Authentication — iris-web CWE-770 5.9 Medium 2026-07-30
CVE-2026-16971 DFIR-IRIS Missing Brute Force Protection in OTP Validation — iris-web CWE-770 5.9 Medium 2026-07-30
CVE-2026-18361 DFIR-IRIS Stored XSS in Datastore Upload — iris-web CWE-79 7.6 High 2026-07-30
CVE-2026-18360 DFIR-IRIS Stored XSS in Custom Attributes — iris-web CWE-79 7.6 High 2026-07-30
CVE-2026-16969 DFIR-IRIS Stored XSS in Assets — iris-web CWE-79 7.6 High 2026-07-30
CVE-2026-42547 IRIS Alerts Can be Falsely Attributed to Customers — iris-web CWE-863 5.4 Medium 2026-06-04
CVE-2026-42543 IRIS has a Cross-Site Request Forgery (CSRF) issue — iris-web CWE-650 4.3 Medium 2026-06-04
CVE-2026-42540 IRIS has a Mass Assignment issue — iris-web CWE-915 4.3 Medium 2026-06-04
CVE-2026-42539 IRIS has an Excessive Data Exposure issue — iris-web CWE-201 6.5 Medium 2026-06-04
CVE-2026-42538 IRIS has an Insecure File Upload — iris-web CWE-434 6.3 Medium 2026-06-04
CVE-2026-42329 Iris has an Open Redirect issue — iris-web CWE-602 4.7 Medium 2026-06-04
CVE-2026-41522 Iris has an Improper Authorization issue — iris-web CWE-285 - - 2026-06-04
CVE-2026-22783 Iris Allows Arbitrary File Deletion via Mass Assignment in Datastore File Management — iris-web CWE-434 9.6 Critical 2026-01-12
CVE-2024-34060 Arbitrary File Write in IRIS EVTX Pipeline — iris-evtx-module CWE-22 8.8 High 2024-05-23
CVE-2024-25624 iris-web vulnerable to Server Side Template Injection in reports — iris-web CWE-1336 6.8 Medium 2024-04-25
CVE-2024-25640 Improper Neutralization of Alternate XSS Syntax in iris-web — iris-web CWE-87 4.6 Medium 2024-02-19
CVE-2023-50712 Improper Neutralization of Alternate XSS Syntax in iris-web — iris-web CWE-87 4.6 Medium 2023-12-22
CVE-2023-30615 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in iris-web — iris-web CWE-80 6.3 Medium 2023-05-25

This page lists every published CVE security advisory associated with dfir-iris. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.