Plasma Workspace Kde Plasma Workspace

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Kde Plasma Workspace.

By the Year

In 2026 there have been 0 vulnerabilities in Kde Plasma Workspace. Plasma Workspace did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 2 5.50
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 2 0.00

It may take a day or so for new Plasma Workspace vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Kde Plasma Workspace Security Vulnerabilities

KSmserver Local ICE Auth Bypass on KDE Plasma <5.27.11.1/6.0.5.1
CVE-2024-36041 7.3 - High - July 05, 2024

KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to gain access to the session manager, e.g., use the session-restore feature to execute arbitrary code as the victim (on the next boot) via earlier use of the /tmp directory.

Insufficient Session Expiration

KDE Plasma 5.93.0 Path Traversal via Theme File Handler
CVE-2024-1433 3.7 - Low - February 11, 2024

A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp of the component Theme File Handler. The manipulation of the argument pluginId leads to path traversal. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The patch is named 6cdf42916369ebf4ad5bd876c4dfa0170d7b2f01. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-253407. NOTE: This requires write access to user's home or the installation of third party global themes.

Directory traversal

An issue was discovered in KDE Plasma Workspace before 5.12.0
CVE-2018-6790 - February 07, 2018

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0
CVE-2018-6791 - February 07, 2018

An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Kde Plasma Workspace or by Kde? Click the Watch button to subscribe.

Kde
Vendor

subscribe