← Back

Kiwire

kiwire

Vendor: Synchroweb • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synchroweb
1Kiwire
Nov 17, 2025
Oct 10, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.
1Synchroweb
1Kiwire
Nov 17, 2025
Oct 10, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.
1Synchroweb
1Kiwire
Nov 14, 2025
Oct 10, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding database.