Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Label Studio MEDIUM 5.4
CVE-2026-22033

Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability e…

Fix: after 1.22.0
Fix from $1,600 2026-01-12
Label Studio Ml Backend HIGH 7.8
CVE-2025-5173

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. A…

Fix: after 2024-09-30
Fix from $1,950 2025-05-26
Label Studio MEDIUM 6.1
CVE-2025-47783

Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious …

Fix: 1.18.0+
Fix from $1,600 2025-05-14
Label Studio HIGH 7.7
CVE-2025-25297

Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Requ…

Fix: 1.16.0+
Fix from $1,950 2025-02-14
Label Studio MEDIUM 6.1
CVE-2025-25296

Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of ar…

Fix: 1.16.0+
Fix from $1,600 2025-02-14
Label Studio MEDIUM 6.1
CVE-2024-26152

### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered wit…

Fix: 1.11.0+
Fix from $1,600 2024-02-22
Label Studio MEDIUM 5.3
CVE-2023-47116

Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on ve…

Fix: 1.11.0+
Fix from $1,600 2024-01-31
Label Studio MEDIUM 6.1
CVE-2024-23633

Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloade…

Fix: 1.10.1+
Fix from $1,600 2024-01-24
Label Studio MEDIUM 5.4
CVE-2023-47115

Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be ex…

Fix: 1.9.2+
Fix from $1,600 2024-01-23
Label Studio HIGH 7.5
CVE-2023-47117

Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insec…

Fix: 1.9.2+
Fix from $1,950 2023-11-13
Label Studio HIGH 8.8
CVE-2023-43791

Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within t…

Fix: 1.8.2+
Fix from $1,950 2023-11-09