Browse all 29 CVE security advisories affecting wireapp. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Wire is an enterprise-grade secure messaging platform designed for encrypted communication among organizations, prioritizing data sovereignty and compliance. With 28 recorded Common Vulnerabilities and Exposures (CVEs), its security history reflects typical web application risks rather than fundamental architectural flaws. The majority of these issues involve cross-site scripting (XSS), SQL injection, and improper access control mechanisms, indicating that most vulnerabilities stem from implementation errors in client-side interfaces or backend API handlers rather than core cryptographic failures. Notably, the platform has not suffered any major public breaches compromising user message content, suggesting that its end-to-end encryption model remains robust against external attacks. However, the frequency of CVEs highlights the ongoing challenge of maintaining rigorous code quality in complex collaborative software. Administrators must prioritize regular patching to mitigate these common exploitation vectors, ensuring that the theoretical security benefits of the platform are preserved in practice.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-35049 | wire-ios has Persistent Remote DoS via Integer Underflow — wire-ios CWE-20 | 6.5 | Medium | 2026-06-02 |
| CVE-2025-49846 | wire-ios accidentally logs message contents — wire-ios CWE-117 | 4.6AI | Medium AI | 2025-07-03 |
| CVE-2022-31009 | DoS vulnerability: Invalid Accent Colors — wire-ios CWE-617 | 5.7 | Medium | 2022-06-23 |
| CVE-2022-23625 | DoS vulnerability: Malformed Resource Identifiers — wire-ios CWE-755 | 6.5 | Medium | 2022-03-11 |
| CVE-2021-41094 | Mandatory encryption at rest can be bypassed (UI) in Wire app — wire-ios CWE-668 | 4.2 | Medium | 2021-10-04 |
| CVE-2021-41093 | Account takeover when having only access to a user's short lived token — wire-ios CWE-285 | 7.4 | High | 2021-10-04 |
| CVE-2021-32666 | Asset DoS vulnerability — wire-ios CWE-20 | 6.5 | Medium | 2021-06-03 |
| CVE-2021-32665 | Verified groups not reliable — wire-ios CWE-345 | 8.8 | High | 2021-06-03 |
| CVE-2021-21301 | Video feed was captured while user has disabled video — wire-ios CWE-200 | 2.6 | Low | 2021-02-11 |
This page lists every published CVE security advisory associated with wireapp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.