« Volver al listado

Circl

Circl AIL Framework: vulnerabilidades y CVE

Circl AIL Framework tiene 13 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses12
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-100190Media (6.3)0.32%—25 sept 2026
The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and…
CVE-2026-100187Media (6.9)0.43%—25 sept 2026
The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending…
CVE-2026-100177Media (6.3)0.34%—25 sept 2026
The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task. The original code…
CVE-2026-100176Alta (8.5)0.35%—25 sept 2026
The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst…
CVE-2026-100174Media (5.1)0.40%—25 sept 2026
The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript…
CVE-2026-100172Alta (8.5)0.27%—25 sept 2026
The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content:…
CVE-2026-76164Alta (7.1)0.40%—19 ago 2026
AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for…
CVE-2026-71445Alta (8.2)0.40%—6 ago 2026
AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML…
CVE-2026-59510Alta (7.1)0.51%—5 jul 2026
AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the…
CVE-2026-56448Alta (8.3)0.44%—22 jun 2026
A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the…
CVE-2026-56138Media (5.3)0.51%—19 jun 2026
AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and…
CVE-2026-39416Alta (8.5)0.30%—8 abr 2026
AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality.…
CVE-2020-8545Alta (7.5)1.3%—3 feb 2020
Global.py in AIL framework 2.8 allows path traversal.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript5
  2. T1189 Drive-by Compromise4
  3. T1210 Exploitation of Remote Services2
  4. T1090.004 Domain Fronting1
  5. T1190 Exploit Public-Facing Application1
  6. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Circl