Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

duck-organization — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting duck-organization. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page presents a comprehensive vulnerability aggregation report for the vendor duck-organization, specifically focusing on software weaknesses and security flaws associated with their product portfolio. The collected data encompasses a wide variety of vulnerability types, ranging from buffer overflows and injection flaws to configuration errors and cryptographic weaknesses, covering security incidents reported from early 2018 through the current year. By synthesizing data from multiple public feeds and vendor advisories, this resource provides a unified view of the threat landscape surrounding duck-organization’s offerings. Readers can use this page to track the timeline of vendor advisories and understand the evolution of specific weakness classes over time. Additionally, users can look up a product's vulnerability history to assess long-term security posture and identify recurring issues. The information is organized to facilitate efficient analysis, allowing security professionals to correlate internal asset inventories with external risk data. This aggregation helps in prioritizing patching efforts and understanding the context of specific CVEs without needing to navigate multiple disparate sources. The content is updated regularly to reflect the latest disclosures and is intended to support proactive risk management and incident response planning. All data points are sourced from verified public records to ensure accuracy and reliability for technical evaluation purposes.

Top products by duck-organization: quest-bot questbot duck-site
CVE IDTitleCVSSSeverityPublished
CVE-2026-49347 Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown — questbotCWE-770--2026-06-12
CVE-2026-48485 Quest Bot: Stored warn reasons can still trigger bot-powered mass mentions through `/warns`. — questbotCWE-116--2026-06-12
CVE-2026-47197 Quest Bot: Discord moderation role hierarchy bypass in ban, kick, mute, unmute, warn, and nickname commands — questbotCWE-862--2026-06-12
CVE-2026-47195 Quest Bot: Per-channel permission overwrite bypass in purge and slowmode commands. — questbotCWE-863--2026-06-12
CVE-2026-47196 Quest Bot: Empty automod rule causes every guild message to be deleted — questbotCWE-20--2026-06-12
CVE-2026-47174 Duck Site: Untrusted pull request code can trigger privileged production deployment — duck-siteCWE-829--2026-06-11
CVE-2026-47189 Quest Bot: AutoMod removal can delete rules from another guild by global rule ID — quest-botCWE-639--2026-06-11
CVE-2026-47188 Quest Bot: Unban and unwarn reason fields still allow bot-powered mass mentions. — quest-botCWE-116--2026-06-11
CVE-2026-47177 Quest Bot: Ticket transcripts can disclose private ticket contents to a lower-visibility channel — quest-botCWE-200--2026-06-11
CVE-2026-47176 Quest Bot: Logging module can disclose private-channel message contents to a lower-visibility log channel — quest-botCWE-200--2026-06-11
CVE-2026-47175 Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` pings — quest-botCWE-116--2026-06-11
CVE-2026-47173 Quest Bot: Ticket reason allows mass-mention injection — quest-botCWE-116--2026-06-11
CVE-2026-47172 Quest Bot: Untrusted pull request code can be built and deployed by privileged `workflow_run` deployment. — quest-botCWE-829--2026-06-11
CVE-2026-47171 Quest Bot: Reminder messages allow stored mass mentions through `@everyone` and `@here` — quest-botCWE-116--2026-06-11
CVE-2026-47163 Quest Bot: Unprivileged users can create and remove AutoMod rules. — quest-botCWE-862--2026-06-11
CVE-2026-47169 Quest Bot: Manage Server users can configure AutoRole to grant Administrator to controlled joining accounts — quest-botCWE-266--2026-06-11

This page lists every published CVE security advisory associated with duck-organization. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.