indico
PyPI15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting indicopage 1 of 1
- CVE-2021-30185HIGHCVSS 7.5EG 7.5fixed in 2.3.42021-04-07
vulnerable: 0.98-rc1 ... 2.3.3 (67 versions)
CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.
- CVE-2023-37901MEDIUMCVSS 5.4EG 5.4fixed in 3.2.62023-07-21
vulnerable: 0.98-rc1 ... 3.2.5 (83 versions)
Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerability in confirmation prompts commonly used when deleting content from Indico. Exploitation requires someone with at least…
- CVE-2024-45399MEDIUMCVSS 4.3EG 4.3fixed in 3.3.42024-09-04
vulnerable: 0.98-rc1 ... 3.3.3 (91 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indico prior to version 3.3.4, corresponding to Flask-Multipass prior to version 0.5.5, there is a Cross-Site-Scripting vul…
- CVE-2024-50633UnratedEG not assessedfixed in 3.3.32025-01-16
vulnerable: 3.2.9, 3.3, 3.3.1, 3.3.2
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the pr…
- CVE-2025-53640MEDIUMCVSS 6.5EG 6.5fixed in 3.3.72025-07-14
vulnerable: 2.2 ... 3.3.6 (40 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (suc…
- CVE-2025-59034MEDIUMCVSS 4.3EG 4.3fixed in 3.3.82025-09-10
vulnerable: 0.98-rc1 ... 3.3.7 (95 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users with…
- CVE-2025-59035MEDIUMCVSS 4.6EG 4.6fixed in 3.3.82025-09-10
vulnerable: 0.98-rc1 ... 3.3.7 (95 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a Cross-Site-Scripting vulnerability when rendering LaTeX math code in contribution or abstra…
- CVE-2026-107394MEDIUMCVSS 6.8EG 6.8fixed in 3.3.132026-10-08
vulnerable: 0.98-rc1 ... 3.3.9 (100 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, the previous fix for CVE-2026-25738 did not cover an edge case, allowing an event organizer to submit a craft…
- CVE-2026-107395MEDIUMCVSS 4.3EG 4.3fixed in 3.3.132026-10-08
vulnerable: 0.98-rc1 ... 3.3.9 (100 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, an authenticated user can misuse the legacy session export API to retrieve details for a restricted session w…
- CVE-2026-107396MEDIUMCVSS 5.4EG 5.4fixed in 3.3.132026-10-08
vulnerable: 0.98-rc1 ... 3.3.9 (100 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted …
- CVE-2026-107397MEDIUMCVSS 4.4EG 4.4fixed in 3.3.132026-10-08
vulnerable: 0.98-rc1 ... 3.3.9 (100 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can create content, including speakers who can create minutes, can store crafted HTML in event minu…
- CVE-2026-25738MEDIUMCVSS 4.3EG 4.3fixed in 3.3.102026-02-19
vulnerable: 0.98-rc1 ... 3.3.9 (97 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to server-side request forgery. Indico makes outgoing requests to user-provides URLs i…
- CVE-2026-25739MEDIUMCVSS 5.4EG 5.4fixed in 3.3.102026-02-19
vulnerable: 0.98-rc1 ... 3.3.9 (97 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain file types as materials. Users should u…
- CVE-2026-28352MEDIUMCVSS 6.5EG 6.5fixed in 3.3.112026-02-27
vulnerable: 0.98-rc1 ... 3.3.9 (98 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing an access check, allowing unauthenticated…
- CVE-2026-33046HIGHCVSS 8.8EG 8.8fixed in 3.3.122026-03-23
vulnerable: 0.98-rc1 ... 3.3.9 (99 versions)
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to vulnerabilities in TeXLive and obscure LaTeX syntax that allowed circumventing Indico's La…
Check whether indico is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for indico CVEs against the assets you own.
Book a Demo →