HIGH8.0CVE-2026-49832DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN >= 8.0-rc1, < 8.4
HIGH7.2CVE-2022-31195DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import >= 4.0, < 5.11
HIGH7.2CVE-2021-41189Communities and collections administrators can escalate their privilege up to system administrator >= 7.0, < 7.1
MEDIUM6.9DSpace is vulnerable to XML External Entity injection during archive imports
from 0, < 7.6.4
MEDIUM5.5DSpace: Path Traversal is possible through LDN message generation
>= 8.0-rc1, < 8.4
MEDIUM5.5DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
from 0, < 7.6.7
MEDIUM5.2DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format
from 0, < 7.6.4
MEDIUM4.4DSpace: ORE resource URI does not validate scheme for non-web resources
from 0, < 7.6.7