Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. DefectDojo/
  3. DefectDojo

DefectDojo

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 30/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 3 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

OWASP Project for making vulnerability management easier.

by DefectDojo · appsec.eu · source ↗

Known CVEs (3)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-7510 ↗MEDIUM 6.32026

    A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulatio…

  • CVE-2026-3816 ↗MEDIUM 4.32026

    A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderPar…

  • CVE-2023-48171 ↗HIGH 8.82024

    An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Vulnerability Management products

see all →
  • A-LIGN Vulnerability Assessment Service · A-LIGN
  • AI EdgeLabs Vulnerability Detection · AI EdgeLabs
  • ASPIA Automated Vulnerability Management System · ASPIA Infotech Pvt. Ltd.
  • Absolute Resilience for Automation · Absolute
  • Action1 Free Initial Vulnerability Assessment · Action1
  • Action1 Patch Compliance Solutions · Action1
  • Action1 Vulnerability Management · Action1
  • Action1 Windows Patch Management · Action1