Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

duck-organization — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting duck-organization. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates all known vulnerabilities affecting products maintained by the vendor Duck-Organization. It collects security advisories covering multiple vulnerability classes, including memory corruption, logic errors, and input validation flaws, spanning the period from 2020 through the present. Users can track the vendor's latest security releases, analyze the frequency and types of weaknesses common to their software stack, and review the complete vulnerability history for specific product lines to assess long-term security trends.

Top products by duck-organization: quest-bot questbot duck-site
CVE ID Title CVSS Severity Published
CVE-2026-49347 Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown — questbot CWE-770 - - 2026-06-12
CVE-2026-48485 Quest Bot: Stored warn reasons can still trigger bot-powered mass mentions through `/warns`. — questbot CWE-116 - - 2026-06-12
CVE-2026-47197 Quest Bot: Discord moderation role hierarchy bypass in ban, kick, mute, unmute, warn, and nickname commands — questbot CWE-862 - - 2026-06-12
CVE-2026-47195 Quest Bot: Per-channel permission overwrite bypass in purge and slowmode commands. — questbot CWE-863 - - 2026-06-12
CVE-2026-47196 Quest Bot: Empty automod rule causes every guild message to be deleted — questbot CWE-20 - - 2026-06-12
CVE-2026-47174 Duck Site: Untrusted pull request code can trigger privileged production deployment — duck-site CWE-829 - - 2026-06-11
CVE-2026-47189 Quest Bot: AutoMod removal can delete rules from another guild by global rule ID — quest-bot CWE-639 - - 2026-06-11
CVE-2026-47188 Quest Bot: Unban and unwarn reason fields still allow bot-powered mass mentions. — quest-bot CWE-116 - - 2026-06-11
CVE-2026-47177 Quest Bot: Ticket transcripts can disclose private ticket contents to a lower-visibility channel — quest-bot CWE-200 - - 2026-06-11
CVE-2026-47176 Quest Bot: Logging module can disclose private-channel message contents to a lower-visibility log channel — quest-bot CWE-200 - - 2026-06-11
CVE-2026-47175 Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` pings — quest-bot CWE-116 - - 2026-06-11
CVE-2026-47173 Quest Bot: Ticket reason allows mass-mention injection — quest-bot CWE-116 - - 2026-06-11
CVE-2026-47172 Quest Bot: Untrusted pull request code can be built and deployed by privileged `workflow_run` deployment. — quest-bot CWE-829 - - 2026-06-11
CVE-2026-47171 Quest Bot: Reminder messages allow stored mass mentions through `@everyone` and `@here` — quest-bot CWE-116 - - 2026-06-11
CVE-2026-47163 Quest Bot: Unprivileged users can create and remove AutoMod rules. — quest-bot CWE-862 - - 2026-06-11
CVE-2026-47169 Quest Bot: Manage Server users can configure AutoRole to grant Administrator to controlled joining accounts — quest-bot CWE-266 - - 2026-06-11

This page lists every published CVE security advisory associated with duck-organization. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.