VendorsCerebrate-Projectcerebrateall versions
Vulnerabilities

Cerebrate-Project Cerebrate

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-28883
In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.
Published 2023-03-27 · Modified
9.8EPSS 0.007
CVE-2023-26468
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.
Published 2023-02-23 · Modified
9.1EPSS 0.006
CVE-2022-25321
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
Published 2022-02-18 · Modified
6.1EPSS 0.011
CVE-2022-25317
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.
Published 2022-02-18 · Modified
6.1EPSS 0.006
CVE-2022-25319
An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
Published 2022-02-18 · Modified
5.3EPSS 0.013
CVE-2022-25320
An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
Published 2022-02-18 · Modified
5.3EPSS 0.009
CVE-2023-41908
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
Published 2023-09-05 · Modified
5.3EPSS 0.004
CVE-2022-25318
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
Published 2022-02-18 · Modified
4.3EPSS 0.006
CVE-2023-41363
In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users.
Published 2023-08-29 · Modified
4.3EPSS 0.004