Defectdojo OWASP Defectdojo

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in OWASP Defectdojo.

By the Year

In 2026 there have been 1 vulnerability in OWASP Defectdojo with an average score of 6.3 out of ten. Defectdojo did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 6.30
2025 0 0.00
2024 1 8.80

It may take a day or so for new Defectdojo vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent OWASP Defectdojo Security Vulnerabilities

OWASP DefectDojo 2.59.0: UserSerializer API Privilege Escalation
CVE-2026-16764 6.3 - Medium - July 23, 2026

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.

Improper Privilege Management

DefectDojo <1.5.3.1 Remote Privilege Escalation via Permissions
CVE-2023-48171 8.8 - High - August 12, 2024

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for OWASP Defectdojo or by OWASP? Click the Watch button to subscribe.

OWASP
Vendor

subscribe