« Volver al listado

Cerebrate-project

Cerebrate-project Cerebrate: vulnerabilidades y CVE

Cerebrate-project Cerebrate tiene 13 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses4
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-53912Media (5.1)0.41%—11 jun 2026
Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s hashed password in the inbox message data payload. This payload was…
CVE-2026-53911Media (6.3)0.35%—11 jun 2026
Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom entity patching flows. In affected entities that did not explicitly mark…
CVE-2026-53901Alta (8.7)0.43%—11 jun 2026
Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacker-supplied id from $params before normalizing the request through…
CVE-2025-66385Crítica (9.4)0.42%—28 nov 2025
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying…
CVE-2023-41908Media (5.3)0.43%—5 sept 2023
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
CVE-2023-41363Media (4.3)0.39%—29 ago 2023
In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users.
CVE-2023-28883Crítica (9.8)0.70%—27 mar 2023
In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.
CVE-2023-26468Crítica (9.1)0.63%—24 feb 2023
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.
CVE-2022-25321Media (6.1)1.1%—18 feb 2022
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
CVE-2022-25320Media (5.3)0.93%—18 feb 2022
An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
CVE-2022-25319Media (5.3)1.3%—18 feb 2022
An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
CVE-2022-25318Media (4.3)0.61%—18 feb 2022
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
CVE-2022-25317Media (6.1)0.62%—18 feb 2022
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1098.002 Additional Email Delegate Permissions1
  2. T1190 Exploit Public-Facing Application1
  3. T1210 Exploitation of Remote Services1
  4. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.