| CVE-2024-43795 | 5.19.0 | Core only | XSS exploit in login screen |
| CVE-2024-46977 | 5.19.0 | Core & Enterprise | Path traversal for .txt files via LocalMode's open_local_file function |
| CVE-2024-47529 | 5.19.0 | Core only | Plaintext storage of password in browser LocalStorage |
| CVE-2025-28380 | 6.0.2 | Core & Enterprise | XSS exploit via crafted URLs to the Documentation Tool or via stored screens with the IFRAME widget in Telemetry Viewer |
| CVE-2025-28381 | 6.0.2 | Core & Enterprise | Certain Docker credentials were leaked through environment variables, readable by authenticated users in Script Runner |
| CVE-2025-28382 | 6.1.0 | Core & Enterprise | Arbitrary file read/copy/delete via the Table Manager API |
| CVE-2025-28384 | 6.1.0 | Core & Enterprise | Arbitrary file read via the Script Runner API |
| CVE-2025-28388 | 6.0.2 | Core only | Hardcoded credentials for the service account (used by running scripts to access the API - no admin permissions) |
| CVE-2025-68271 | 6.10.2 | Core & Enterprise | Critical remote code execution vulnerability reachable through the JSON-RPC API by an unauthenticated attacker |