Product
konga project konga
4 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-34243
CVE-2023-39846
CVE-2023-26987
CVE-2021-42192
all versions
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
all versions
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
all versions
An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST r
all versions
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege esc