altium 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
一般的な弱点パターンには vendor risk cross-site scripting、vendor risk sql injection, and vendor risk input validation があり、vendor surface production workloads の利用場面で vendor impact session compromise、vendor impact unexpected behavior, and vendor impact data exposure などのリスクが生じる可能性があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2025-27380 | HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML content. | 4760f414-e1ae-4ff1-bdad-c7a9c3538b79 | 7.6 | 0.03% | 2026-01-22 | 2026-02-26 |
| CVE-2025-27379 | A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field of a schematic, which is executed when the BOM Viewer renders the affected content. | 4760f414-e1ae-4ff1-bdad-c7a9c3538b79 | 6.8 | 0.03% | 2026-01-22 | 2026-02-26 |
| CVE-2025-27378 | AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted input may be improperly handled, allowing attackers to inject and execute arbitrary SQL queries. | 4760f414-e1ae-4ff1-bdad-c7a9c3538b79 | 8.6 | 0.04% | 2026-01-22 | 2026-02-26 |
| CVE-2025-27377 | Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data. | 4760f414-e1ae-4ff1-bdad-c7a9c3538b79 | 5.3 | 0.02% | 2026-01-22 | 2026-02-26 |
| CVE-2026-1011 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interface applies HTML escaping, the backend accepts and stores arbitrary HTML and JavaScript supplied via modified POST requests. The injected content is rendered verbatim when support cases are viewed by other users, including support staff with elevated privileges, allowing execution of arbitrary JavaScript in the victim’ | 4760f414-e1ae-4ff1-bdad-c7a9c3538b79 | 6.1 | 0.04% | 2026-01-16 | 2026-01-23 |
| CVE-2026-1010 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow, the injected payload executes in the administrator’s browser context, allowing privilege escalation, including creation of new administrator accounts, session token theft, and execution of administrat | 4760f414-e1ae-4ff1-bdad-c7a9c3538b79 | 8.0 | 0.04% | 2026-01-15 | 2026-01-23 |
| CVE-2026-1009 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts, which is stored and executed when other users view the affected post. Successful exploitation allows the attacker’s payload to execute in the context of the victim’s authenticated Altium 365 session, enabling unauthorized access to workspace data, including design files and wor | 4760f414-e1ae-4ff1-bdad-c7a9c3538b79 | 9.0 | 0.04% | 2026-01-15 | 2026-01-23 |
| CVE-2026-1008 | A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization allows authenticated users to inject arbitrary HTML and JavaScript payloads using whitespace-based attribute parsing bypass techniques. The injected payload is persisted and executed when other users view the affected profile page, potentially allowing session token theft, phishing attacks, or malicious redirects. Exploitation requires an authenticat | 4760f414-e1ae-4ff1-bdad-c7a9c3538b79 | 7.6 | 0.03% | 2026-01-15 | 2026-01-23 |