Circl
Circl AIL Framework: vulnerabilidades y CVE
Circl AIL Framework tiene 13 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses12
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100190 | Media (6.3) | 0.32% | — | 25 sept 2026 | The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and… |
| CVE-2026-100187 | Media (6.9) | 0.43% | — | 25 sept 2026 | The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending… |
| CVE-2026-100177 | Media (6.3) | 0.34% | — | 25 sept 2026 | The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task. The original code… |
| CVE-2026-100176 | Alta (8.5) | 0.35% | — | 25 sept 2026 | The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst… |
| CVE-2026-100174 | Media (5.1) | 0.40% | — | 25 sept 2026 | The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript… |
| CVE-2026-100172 | Alta (8.5) | 0.27% | — | 25 sept 2026 | The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content:… |
| CVE-2026-76164 | Alta (7.1) | 0.40% | — | 19 ago 2026 | AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can submit an arbitrary URL for… |
| CVE-2026-71445 | Alta (8.2) | 0.40% | — | 6 ago 2026 | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML… |
| CVE-2026-59510 | Alta (7.1) | 0.51% | — | 5 jul 2026 | AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the… |
| CVE-2026-56448 | Alta (8.3) | 0.44% | — | 22 jun 2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the… |
| CVE-2026-56138 | Media (5.3) | 0.51% | — | 19 jun 2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and… |
| CVE-2026-39416 | Alta (8.5) | 0.30% | — | 8 abr 2026 | AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality.… |
| CVE-2020-8545 | Alta (7.5) | 1.3% | — | 3 feb 2020 | Global.py in AIL framework 2.8 allows path traversal. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.