VendorsCerebrate-Projectcerebrateany version
Vulnerabilities

Cerebrate-Project Cerebrate any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-25321
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
Published 2022-02-18 · Modified
6.1EPSS 0.011
CVE-2022-25317
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.
Published 2022-02-18 · Modified
6.1EPSS 0.006
CVE-2022-25319
An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
Published 2022-02-18 · Modified
5.3EPSS 0.013
CVE-2022-25320
An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
Published 2022-02-18 · Modified
5.3EPSS 0.009
CVE-2023-41908
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
Published 2023-09-05 · Modified
5.3EPSS 0.004
CVE-2022-25318
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
Published 2022-02-18 · Modified
4.3EPSS 0.006