Vulnerabilities > Qanything

DATE CVE VULNERABILITY TITLE RISK
2025-03-20 CVE-2024-8026 Unspecified vulnerability in Qanything
A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc.
network
low complexity
qanything
8.1
2024-02-11 CVE-2024-25722 SQL Injection vulnerability in Qanything
qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.
network
low complexity
qanything CWE-89
critical
9.8