Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Kiteworks/
  3. Kiteworks Cybersecurity Risk Management

Kiteworks Cybersecurity Risk Management

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 33 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Platform for managing cybersecurity risk and regulatory compliance

by Kiteworks · kiteworks.com · source ↗

Known CVEs (33)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-24782 ↗HIGH 7.62026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuil…

  • CVE-2026-24761 ↗LOW 3.72026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to access metada…

  • CVE-2026-24756 ↗MEDIUM 4.32026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resour…

  • CVE-2026-24755 ↗MEDIUM 5.42026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify permis…

  • CVE-2026-24754 ↗MEDIUM 5.42026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code …

  • CVE-2026-24753 ↗MEDIUM 6.52026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resour…

  • CVE-2026-24752 ↗HIGH 8.22026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrar…

  • CVE-2026-24751 ↗HIGH 8.22026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrar…

  • CVE-2026-23638 ↗MEDIUM 6.52026

    Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper wi…

  • CVE-2026-29092 ↗MEDIUM 4.92026

    Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their…

  • CVE-2026-23636 ↗MEDIUM 5.52026

    Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an Unrestricted Upload of File with Dangerous Type due…

  • CVE-2026-23635 ↗MEDIUM 6.52026

    Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could potentially lead to Unprotected Transport of Crede…

  • CVE-2026-24750 ↗HIGH 7.62026

    Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper Neutralization of Input During Web Page Generation…

  • CVE-2026-23514 ↗HIGH 8.82026

    Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kitew…

  • CVE-2026-28272 ↗HIGH 8.12026

    Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a confi…

  • CVE-2026-28271 ↗MEDIUM 6.52026

    Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Maliciou…

  • CVE-2026-28270 ↗MEDIUM 4.92026

    Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators co…

  • CVE-2026-28269 ↗MEDIUM 5.92026

    Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file l…

  • CVE-2025-53939 ↗MEDIUM 6.32025

    Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly elevate another user's permissions on the…

  • CVE-2025-53900 ↗MEDIUM 6.52025

    Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpe…

  • …and 13 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Managed File Transfer products

see all →
  • CSS Antivirus for Managed File Transfers · Cloud Storage Security
  • Kiteworks AI Data Gateway · Kiteworks
  • Kiteworks Secure Managed File Transfer · Kiteworks
  • OPSWAT MetaDefender Managed File Transfer (MFT) · OPSWAT
  • Sasa Software GateScanner Security Dome · Sasa Software
  • Tectia SSH Server for IBM z/OS · SSH Communications Security
  • Zertificon Z1 Energy · Zertificon Solutions GmbH