cerebrate-project CVE Vulnerabilities & CVE List (9)

Products (CPE): — CVEs: 9

cerebrate-project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all cerebrate-project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk sql injection and related problems; some flaws may lead to vendor impact session compromise.

Vulnerability distribution trend (last 24 months)

Showing 19 of 9 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-41908 Cerebrate before 1.15 lacks the Secure attribute for the session cookie. [email protected] 5.3 0.36% 2023-09-05 2024-11-21
CVE-2023-41363 In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users. [email protected] 4.3 0.33% 2023-08-29 2024-11-21
CVE-2023-28883 In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint. [email protected] 9.8 0.70% 2023-03-27 2025-02-19
CVE-2023-26468 Cerebrate 1.12 does not properly consider organisation_id during creation of API keys. [email protected] 9.1 0.63% 2023-02-24 2024-11-21
CVE-2022-25321 An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. [email protected] 6.1 1.05% 2022-02-18 2024-11-21
CVE-2022-25320 An issue was discovered in Cerebrate through 1.4. Username enumeration could occur. [email protected] 5.3 0.90% 2022-02-18 2024-11-21
CVE-2022-25319 An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled. [email protected] 5.3 1.31% 2022-02-18 2024-11-21
CVE-2022-25318 An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups. [email protected] 4.3 0.57% 2022-02-18 2024-11-21
CVE-2022-25317 An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description. [email protected] 6.1 0.60% 2022-02-18 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence