Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/kiteworks/secure-data-forms

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Kiteworks Secure Data Forms versions prior to 9.3.0 contain multiple SQL Injection vulnerabilities. These can be exploited by an authenticated attacker with the FormBuilder role to access or modify other users' form definitions and some global configuration parameters. The vulnerability is addressed in version 9.3.0 and later.

Join the discussion

An Insecure Direct Object Reference (IDOR) vulnerability exists in kiteworks Secure Data Forms prior to version 9.3.0. This vulnerability allows an authenticated user to access metadata of resources owned by other users due to insufficient authorization checks. The issue is resolved by upgrading to version 9.3.0 or later.

Join the discussion

An authorization bypass vulnerability (CWE-639) exists in Kiteworks Secure Data Forms prior to version 9.3.0. This Insecure Direct Object Reference (IDOR) flaw allows an authenticated user to modify resources owned by other users due to insufficient authorization checks. The vulnerability has a medium severity with a CVSS score of 4.3. Upgrading to version 9.3.0 or later addresses this issue.

Join the discussion

Kiteworks Secure Data Forms prior to version 9.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to modify resources owned by other users due to insufficient authorization checks. This vulnerability is addressed in version 9.3.0 and later.

Join the discussion

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.

Join the discussion

An authorization bypass vulnerability (CWE-639) exists in Kiteworks Secure Data Forms versions prior to 9.3.0. This Insecure Direct Object Reference (IDOR) flaw allows an authenticated attacker to manipulate approval flow configurations of forms owned by other users due to insufficient authorization checks. The vulnerability has a CVSS score of 6.5 (medium severity). No known exploits are reported in the wild. Users should upgrade to version 9.3.0 or later to address this issue.

Join the discussion

CVE-2026-23636 is a medium severity vulnerability in Kiteworks Secure Data Forms prior to version 9.2.1. It involves an unrestricted upload of files with dangerous types due to missing validation, which could be exploited by a form manager. This vulnerability can lead to integrity impact but does not affect confidentiality. A patch is available in Kiteworks version 9.2.1 and later.

Join the discussion

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could potentially lead to Unprotected Transport of Credentials under certain circumstances. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/kiteworks/secure-data-forms
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses