Vulnerabilities > Quivr

DATE CVE VULNERABILITY TITLE RISK
2024-07-07 CVE-2024-6229 Unspecified vulnerability in Quivr
A stored cross-site scripting (XSS) vulnerability exists in the 'Upload Knowledge' feature of stangirard/quivr, affecting the latest version.
network
low complexity
quivr
5.4
2024-06-27 CVE-2024-5885 Unspecified vulnerability in Quivr 0.0.236
stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability.
network
low complexity
quivr
8.6
2024-06-06 CVE-2024-4851 Unspecified vulnerability in Quivr 0.0.204
A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access internal networks.
network
low complexity
quivr
7.7