Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

dfir-iris — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting dfir-iris. AI-powered Chinese analysis, POCs, and references for each vulnerability.

DFIR-IRIS is a digital forensics and incident response platform designed for comprehensive security investigations and threat hunting. Historically, it has been associated with vulnerabilities including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, with six CVEs documented to date. The platform's security characteristics focus on robust evidence collection and analysis capabilities, though specific major incidents remain undisclosed. Its core use case centers on enabling security teams to conduct thorough forensic examinations, detect advanced threats, and respond effectively to security breaches across complex IT environments.

Top products by dfir-iris: iris-web iris-evtx-module
CVE IDTitleCVSSSeverityPublished
CVE-2026-16970 DFIR-IRIS Insufficient Logout Implementation — iris-webCWE-613 4.2 Medium2026-07-30
CVE-2026-18362 DFIR-IRIS Missing Brute Force Protection in User Authentication — iris-webCWE-770 5.9 Medium2026-07-30
CVE-2026-16971 DFIR-IRIS Missing Brute Force Protection in OTP Validation — iris-webCWE-770 5.9 Medium2026-07-30
CVE-2026-18361 DFIR-IRIS Stored XSS in Datastore Upload — iris-webCWE-79 7.6 High2026-07-30
CVE-2026-18360 DFIR-IRIS Stored XSS in Custom Attributes — iris-webCWE-79 7.6 High2026-07-30
CVE-2026-16969 DFIR-IRIS Stored XSS in Assets — iris-webCWE-79 7.6 High2026-07-30
CVE-2026-42547 IRIS Alerts Can be Falsely Attributed to Customers — iris-webCWE-863 5.4 Medium2026-06-04
CVE-2026-42543 IRIS has a Cross-Site Request Forgery (CSRF) issue — iris-webCWE-650 4.3 Medium2026-06-04
CVE-2026-42540 IRIS has a Mass Assignment issue — iris-webCWE-915 4.3 Medium2026-06-04
CVE-2026-42539 IRIS has an Excessive Data Exposure issue — iris-webCWE-201 6.5 Medium2026-06-04
CVE-2026-42538 IRIS has an Insecure File Upload — iris-webCWE-434 6.3 Medium2026-06-04
CVE-2026-42329 Iris has an Open Redirect issue — iris-webCWE-602 4.7 Medium2026-06-04
CVE-2026-41522 Iris has an Improper Authorization issue — iris-webCWE-285--2026-06-04
CVE-2026-22783 Iris Allows Arbitrary File Deletion via Mass Assignment in Datastore File Management — iris-webCWE-434 9.6 Critical2026-01-12
CVE-2024-34060 Arbitrary File Write in IRIS EVTX Pipeline — iris-evtx-moduleCWE-22 8.8 High2024-05-23
CVE-2024-25624 iris-web vulnerable to Server Side Template Injection in reports — iris-webCWE-1336 6.8 Medium2024-04-25
CVE-2024-25640 Improper Neutralization of Alternate XSS Syntax in iris-web — iris-webCWE-87 4.6 Medium2024-02-19
CVE-2023-50712 Improper Neutralization of Alternate XSS Syntax in iris-web — iris-webCWE-87 4.6 Medium2023-12-22
CVE-2023-30615 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in iris-web — iris-webCWE-80 6.3 Medium2023-05-25

This page lists every published CVE security advisory associated with dfir-iris. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.