Monkeytype

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-69183

    Monkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass)

    Last Modified: Aug 21, 2026
    Published: Aug 20, 2026

    CVE-2025-66563

    Monkeytype vulnerable to stored XSS in approve quotes page

    Last Modified: Dec 17, 2025
    Published: Dec 04, 2025

    CVE-2025-59838

    Monkeytype Vulnerable to Self-XSS on loading saved custom text

    Last Modified: Oct 28, 2025
    Published: Sep 25, 2025

    CVE-2024-41127

    Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its `ci-failure-comment.yml` GitHub Workflow, enabling attackers to gain `pull-requests` write access.

    Last Modified: Sep 11, 2024
    Published: Aug 02, 2024
    Items Per Page