Cti-transmute
Cti-transmute: vulnerabilidades y CVE
Cti-transmute tiene 12 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses12
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73161 | Media (5.1) | 0.40% | — | 11 ago 2026 | Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function previously returned the underlying text directly when no search query… |
| CVE-2026-73160 | Alta (8.7) | 0.41% | — | 11 ago 2026 | Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself an IP literal and… |
| CVE-2026-73158 | Media (5.1) | 0.40% | — | 11 ago 2026 | Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are later consumed by Pivotick, and Pivotick interprets svgIcon as HTML.… |
| CVE-2026-73157 | Baja (2.3) | 0.44% | — | 11 ago 2026 | Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization names,… |
| CVE-2026-73156 | Media (5.3) | 0.44% | — | 11 ago 2026 | Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including STIX types,… |
| CVE-2026-73155 | Media (5.3) | 0.35% | — | 11 ago 2026 | Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view the target comment. The vulnerable react()… |
| CVE-2026-73140 | Media (5.3) | 0.35% | — | 11 ago 2026 | Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility,… |
| CVE-2026-72751 | Media (5.1) | 0.45% | — | 10 ago 2026 | CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise converted MISP and STIX content. Attacker-controlled values originating from converted CTI data… |
| CVE-2026-71502 | Media (5.1) | 0.74% | — | 8 ago 2026 | CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can… |
| CVE-2026-69082 | Alta (8.8) | 0.27% | — | 3 ago 2026 | CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation that modified… |
| CVE-2026-69079 | Alta (8.7) | 0.54% | — | 3 ago 2026 | CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a… |
| CVE-2026-69078 | Alta (8.8) | 0.41% | — | 3 ago 2026 | CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.