vciy

CVEs we hold for Wireapp

Records whose assigning authority named Wireapp as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-35049wire-ios has Persistent Remote DoS via Integer Underflowwireapp wire-ios
CVE-2025-49846wire-ios accidentally logs message contentswireapp wire-ios
CVE-2025-48066wire-webapp has no database deletion on client logoutwireapp wire-webapp
CVE-2025-48061wire-webapp Has Insufficient Session Invalidation after User Logoutwireapp wire-webapp
CVE-2023-48221wire-avs remote format string vulnerabilitywireapp wire-avs
CVE-2023-22737wire-server vulnerable to unauthorized removal of Bots from Conversationswireapp wire-server
CVE-2022-39380wire-webapp contains Improper Handling of Exceptional Conditions leading to a DoS via Markdown Renderingwireapp wire-webapp
CVE-2022-31122Wire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account…wireapp wire-server
CVE-2022-31009DoS vulnerability: Invalid Accent Colorswireapp wire-ios
CVE-2022-29168Cross Site Scripting in Wire Messageswireapp wire-webapp
CVE-2022-24799Cross Site Scripting in Wire Webappwireapp wire-webapp
CVE-2022-23625DoS vulnerability: Malformed Resource Identifierswireapp wire-ios
CVE-2022-23610Improper Verification of Cryptographic Signature in wire-serverwireapp wire-server
CVE-2022-23605Expired Ephemeral Messages not reliably removed in wire-webappwireapp wire-webapp
CVE-2021-41193Use of Externally-Controlled Format String in wire-avswireapp wire-avs
CVE-2021-41119DoS vulnerabiliity in wire-server json parserwireapp wire-server
CVE-2021-41101CORS `Access-Control-Allow-Origin` settings are too lenientwireapp wire-server
CVE-2021-41100Account takeover when having only access to a user's short lived token in wire-serverwireapp wire-server
CVE-2021-41094Mandatory encryption at rest can be bypassed (UI) in Wire appwireapp wire-ios
CVE-2021-41093Account takeover when having only access to a user's short lived tokenwireapp wire-ios
CVE-2021-32755Certificate pinning is not enforced on the web socket connectionwireapp wire-ios-transport
CVE-2021-32683XSS through createObjectURLwireapp wire-webapp
CVE-2021-32666Asset DoS vulnerabilitywireapp wire-ios
CVE-2021-32665Verified groups not reliablewireapp wire-ios
CVE-2021-21400Entering code in App Lock modal sends input to conversationwireapp wire-webapp
CVE-2021-21396Bulk list client endpoint exposes too much metadata about a clientwireapp wire-server
CVE-2021-21382Unsafe loopback forwarding interface in Restundwireapp restund
CVE-2021-21301Video feed was captured while user has disabled videowireapp wire-ios
CVE-2020-15258Insecure use of shell.openExternal in Wirewireapp wire-desktop

29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.