Epiphany
This hub aggregates every CVE we track for Epiphany, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
0
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM8HIGH7
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Epiphany.
- CVE-2026-18487Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()5.4
- CVE-2025-3839Epiphany: insecure external protocol invocation in epiphany8.0
- CVE-2023-26081In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.7.5
- CVE-2022-29536In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because ...7.5
- CVE-2021-45086XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.6.1
- CVE-2021-45087XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.6.1
- CVE-2021-45088XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.6.1
- CVE-2021-45085XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place th...6.1
- CVE-2019-6251WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for...8.1
- CVE-2018-12016libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls.7.5
- CVE-2018-11396ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a ...7.5
- CVE-2017-1000025GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote ex...7.5
- CVE-2010-3312Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the user, which allows ...5.8
- CVE-2008-5985Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the curre...6.9
- CVE-2005-0238The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that...5.0
Product normalization is registry-driven with AI assist and human review. How it works