CKAN vulnerable to fixed session IDs
Modified: 7/7/2026
package
pkg:pypi/ckan
CKAN vulnerable to fixed session IDs
Modified: 7/7/2026
CKAN vulnerable to stored XSS in resource description
Modified: 7/7/2026
CKAN may leak Solr credentials via error message in package_search action
Modified: 7/7/2026
Ckan remote code execution and private information access via crafted resource ids
Modified: 9/10/2026
Cross-site Scripting in CKAN
Modified: 9/13/2024
Out of memory error when submitting the dataset form with a specially-crafted field
Modified: 9/10/2026
CKAN has an XSS vector in user uploaded images in group/org and user profiles
Modified: 7/7/2026
Potential log injection in reset user endpoint in CKAN
Modified: 9/10/2026
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
Modified: 7/13/2026
Potential access to sensitive URLs via CKAN extensions (SSRF)
Modified: 7/7/2026
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
Modified: 7/13/2026
CKAN contains Improper Authentication leading to account takeover
Modified: 4/29/2025
CKAN has CSRF exemption primed by anonymous requests
Modified: 7/13/2026
CKAN has no certificate validation on STMP connection
Modified: 7/13/2026
CKAN has Cross-site Scripting vector in the Datatables view plugin
Modified: 7/7/2026
Modified: 11/8/2023
Modified: 6/10/2026
CKAN vulnerable to fixed session IDs
Modified: 7/7/2026
CKAN vulnerable to stored XSS in resource description
Modified: 7/7/2026
CKAN may leak Solr credentials via error message in package_search action
Modified: 7/7/2026
Out of memory error when submitting the dataset form with a specially-crafted field
Modified: 7/7/2026
CKAN has an XSS vector in user uploaded images in group/org and user profiles
Modified: 7/7/2026
Potential log injection in reset user endpoint in CKAN
Modified: 7/7/2026
Potential access to sensitive URLs via CKAN extensions (SSRF)
Modified: 7/7/2026
CKAN has Cross-site Scripting vector in the Datatables view plugin
Modified: 7/7/2026
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
Modified: 7/13/2026
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
Modified: 7/13/2026
CKAN has CSRF exemption primed by anonymous requests
Modified: 7/13/2026
CKAN has no certificate validation on STMP connection
Modified: 7/13/2026
Ckan remote code execution and private information access via crafted resource ids
Modified: 7/2/2026