Home / CVEs we hold for Wireapp CVEs we hold for Wireapp Records whose assigning authority named Wireapp as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-35049 wire-ios has Persistent Remote DoS via Integer Underflow wireapp wire-ios CVE-2025-49846 wire-ios accidentally logs message contents wireapp wire-ios CVE-2025-48066 wire-webapp has no database deletion on client logout wireapp wire-webapp CVE-2025-48061 wire-webapp Has Insufficient Session Invalidation after User Logout wireapp wire-webapp CVE-2023-48221 wire-avs remote format string vulnerability wireapp wire-avs CVE-2023-22737 wire-server vulnerable to unauthorized removal of Bots from Conversations wireapp wire-server CVE-2022-39380 wire-webapp contains Improper Handling of Exceptional Conditions leading to a DoS via Markdown Rendering wireapp wire-webapp CVE-2022-31122 Wire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account… wireapp wire-server CVE-2022-31009 DoS vulnerability: Invalid Accent Colors wireapp wire-ios CVE-2022-29168 Cross Site Scripting in Wire Messages wireapp wire-webapp CVE-2022-23625 DoS vulnerability: Malformed Resource Identifiers wireapp wire-ios CVE-2022-23610 Improper Verification of Cryptographic Signature in wire-server wireapp wire-server CVE-2022-23605 Expired Ephemeral Messages not reliably removed in wire-webapp wireapp wire-webapp CVE-2021-41193 Use of Externally-Controlled Format String in wire-avs wireapp wire-avs CVE-2021-41119 DoS vulnerabiliity in wire-server json parser wireapp wire-server CVE-2021-41101 CORS `Access-Control-Allow-Origin` settings are too lenient wireapp wire-server CVE-2021-41100 Account takeover when having only access to a user's short lived token in wire-server wireapp wire-server CVE-2021-41094 Mandatory encryption at rest can be bypassed (UI) in Wire app wireapp wire-ios CVE-2021-41093 Account takeover when having only access to a user's short lived token wireapp wire-ios CVE-2021-32755 Certificate pinning is not enforced on the web socket connection wireapp wire-ios-transport CVE-2021-21400 Entering code in App Lock modal sends input to conversation wireapp wire-webapp CVE-2021-21396 Bulk list client endpoint exposes too much metadata about a client wireapp wire-server CVE-2021-21382 Unsafe loopback forwarding interface in Restund wireapp restund CVE-2021-21301 Video feed was captured while user has disabled video wireapp wire-ios CVE-2020-15258 Insecure use of shell.openExternal in Wire wireapp wire-desktop 29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.