« Volver al listado

Bluewavelabs

Bluewavelabs Checkmate: vulnerabilidades y CVE

Bluewavelabs Checkmate tiene 12 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses9
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85390Alta (7.1)0.49%—3 sept 2026
Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role…
CVE-2026-36102Alta (7.2)0.58%—27 ago 2026
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
CVE-2026-71862Alta (7.5)0.48%—21 ago 2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global…
CVE-2026-70656Media (4.9)0.59%—21 ago 2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated…
CVE-2026-55241Alta (7.5)0.62%—21 ago 2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST…
CVE-2026-72588Media (5.3)0.42%—10 ago 2026
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request…
CVE-2026-14829Alta (8.2)0.33%—6 ago 2026
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed…
CVE-2026-31836Alta (8.1)0.36%—20 mar 2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass…
CVE-2026-30829Media (5.3)0.41%—7 mar 2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to version 3.4.0, an unauthenticated…
CVE-2025-48024Media (5)0.34%—15 may 2025
In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.
CVE-2025-47817Alta (8.8)0.50%—10 may 2025
In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.
CVE-2025-47245Alta (8.1)0.50%—4 may 2025
In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1210 Exploitation of Remote Services4
  3. T1068 Exploitation for Privilege Escalation3
  4. T1078 Valid Accounts1
  5. T1078.001 Default Accounts1
  6. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.