Executive brief
CKAN has an XSS vector in user uploaded images in group/org and user profiles
Affected products
- PyPI ckan
Junglewise Threat Intelligence
CVE-2025-24372 · Severity: low · CVSS 3.1 · Published 2026-07-07
Technologies: ckan (PyPI). Vendors: PyPI.
CKAN has an XSS vector in user uploaded images in group/org and user profiles