Known Vulnerabilities

Known Vulnerabilities

Here you can find a list of all currently known vulnerabilities for our products. The vulnerabilities are given in CVSS (Common Vulnerability Scoring System) format. Any steps that can be taken to fix, patch, or mitigate the vulnerabilities will be included.

Date

Affected Product(s)

Vulnerability

Severity (CVSS 3.0)

Fix ETA

Fixed versions

Responsible for patching

Date

Affected Product(s)

Vulnerability

Severity (CVSS 3.0)

Fix ETA

Fixed versions

Responsible for patching

Jan 6, 2026

samedi-app

CVE-2025-14847: MongoDB in samedi-app erlaubt Extraktion sensibler Daten

5.5 - 6.5 (depends on configuration)

Fixed

v32.4.0

Customer

May 13, 2026

samedi App

WID-SEC-2026-1516: Mehrere Schwachstellen in MongoDB betreffen samedi-app

5.5

May 19, 2026

v32.4.3 (not yet available)

Customer