VendorsCiteumopenctiany version
Vulnerabilities

Citeum OpenCTI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2026-27960
OpenCTI privilege escalation and unauthenticated access via default admin account
Published 2026-05-05 · Analyzed
9.8EPSS 0.018
CVE-2025-24977
OpenCTI has remote code execution and sensitive secrets exposed through web hook
Published 2025-05-05 · Analyzed
9.1EPSS 0.008
CVE-2026-39980
OpenCTI affected by RCE via notifier template
Published 2026-04-09 · Analyzed
9.1EPSS 0.007
CVE-2025-61781
GraphQL IDOR allows authenticated user to delete workspace content of other users
Published 2026-01-05 · Analyzed
9.1EPSS 0.002
CVE-2024-26139
OpenCTI Authenticated Privilege Escalation
Published 2024-05-23 · Analyzed
8.3EPSS 0.004
CVE-2024-37155
OpenCTI May Bypass Introspection Restriction
Published 2024-11-18 · Analyzed
8.2EPSS 0.005
CVE-2024-45404
OpenCTI's lack of Rate Limit lead to OTP brute forcing
Published 2024-12-11 · Analyzed
8.1EPSS 0.006
CVE-2026-21886
OpenCTI's GraphQL Mutations Allow Deletion of Unrelated Entities
Published 2026-03-17 · Analyzed
8.1EPSS 0.002
CVE-2026-21887
OpenCTI has a Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
Published 2026-03-12 · Analyzed
7.7EPSS 0.002
CVE-2025-26621
OpenCTI vulnerable to Denial of Service through web hook
Published 2025-05-19 · Analyzed
7.6EPSS 0.004
CVE-2022-30290
In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker can abuse the identified vulnerability in order to arbitrarily change their registered e-mail address as well as their API key, even though such action is not possible through the interface, legitimately.
Published 2022-07-05 · Modified
7.5EPSS 0.010
CVE-2026-44730
OpenCTI: Privilege escalation via graphQL API abusable by organization admins, due to incorrect ACL on userEdit relationAdd
Published 2026-05-26 · Analyzed
7.2EPSS 0.005
CVE-2026-35210
OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
Published 2026-07-08 · Analyzed
7.1EPSS 0.004
CVE-2026-35211
OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoS
Published 2026-07-08 · Analyzed
6.5EPSS 0.005
CVE-2025-24887
OpenCTI bypass of protected attribute update
Published 2025-04-30 · Analyzed
6.3EPSS 0.002
CVE-2025-61782
Open Redirect in OpenCTI's SAML Authentication Flow
Published 2026-01-07 · Analyzed
6.1EPSS 0.003
CVE-2026-35212
OpenCTI has XSS in the rendering of email-message observable body data
Published 2026-06-02 · Analyzed
6.1EPSS 0.003
CVE-2022-30289
A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2.4. An attacker can abuse the vulnerability to upload a malicious file that will then be executed by a victim when they open the file location.
Published 2022-07-05 · Modified
5.4EPSS 0.005
CVE-2025-46732
OpenCTI's GraphQL IDOR enables authenticated users to modify or delete notifications of other users
Published 2025-07-18 · Analyzed
5.4EPSS 0.002
CVE-2024-45805
OpenCTI leaks support information due to inadequate access control
Published 2024-12-26 · Analyzed
4.3EPSS 0.003