Vulnerabilities (CVE)

Filtered by vendor Cinnamon Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-56527 1 Cinnamon 1 Kotaemon 2025-12-02 N/A 7.5 HIGH
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
CVE-2025-56526 1 Cinnamon 1 Kotaemon 2025-12-02 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.