Security: DefectDojo/django-DefectDojo
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Cross-product engagement preset disclosure in DefectDojoGHSA-x7vh-q84w-mcw2 published
Sep 4, 2026 by svader0Moderate -
Improper Authorization Allows a Non-Staff Product Member to Delete FindingsGHSA-rw9h-7pr2-3wjp published
Sep 4, 2026 by svader0Moderate -
Cross-product Disclosure of Location Tags in DefectDojoGHSA-rr5c-4hrj-f5wp published
Sep 4, 2026 by svader0Moderate -
Finding Templates Readable via the Add-From-Template ListingGHSA-f252-9gq4-g2m4 published
Sep 4, 2026 by svader0Moderate -
Cross-Product Disclosure of Product and Finding Metadata Through the Endpoint List FiltersGHSA-2pq7-j824-gpc5 published
Sep 4, 2026 by svader0Moderate -
Cross-Product Authorization Gap in V3 Locations Allows an Authenticated User to Modify Other Products' Endpoint RecordsGHSA-p3vg-56r7-3qf8 published
Sep 4, 2026 by svader0Moderate -
Cross-product deletion of a shared Location and its references in the V3 Locations featureGHSA-5r5c-m32h-w93x published
Sep 4, 2026 by svader0Moderate -
Missing Authorization on Open Questionnaire Write Operations in DefectDojo ProGHSA-vxvf-jjrg-26w8 published
Sep 4, 2026 by svader0Moderate -
Cross-product disclosure of finding data through the DefectDojo Pro compliance moduleGHSA-wf7g-4v94-85qm published
Aug 24, 2026 by svader0Moderate -
Cross-product disclosure of finding data through the scan import preview API in DefectDojo ProGHSA-67w9-42qx-7mcg published
Aug 24, 2026 by svader0Moderate