« Volver al listado

Cti-transmute

Cti-transmute: vulnerabilidades y CVE

Cti-transmute tiene 12 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses12
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-73161Media (5.1)0.40%—11 ago 2026
Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function previously returned the underlying text directly when no search query…
CVE-2026-73160Alta (8.7)0.41%—11 ago 2026
Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself an IP literal and…
CVE-2026-73158Media (5.1)0.40%—11 ago 2026
Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are later consumed by Pivotick, and Pivotick interprets svgIcon as HTML.…
CVE-2026-73157Baja (2.3)0.44%—11 ago 2026
Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization names,…
CVE-2026-73156Media (5.3)0.44%—11 ago 2026
Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including STIX types,…
CVE-2026-73155Media (5.3)0.35%—11 ago 2026
Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view the target comment. The vulnerable react()…
CVE-2026-73140Media (5.3)0.35%—11 ago 2026
Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility,…
CVE-2026-72751Media (5.1)0.45%—10 ago 2026
CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise converted MISP and STIX content. Attacker-controlled values originating from converted CTI data…
CVE-2026-71502Media (5.1)0.74%—8 ago 2026
CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can…
CVE-2026-69082Alta (8.8)0.27%—3 ago 2026
CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation that modified…
CVE-2026-69079Alta (8.7)0.54%—3 ago 2026
CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a…
CVE-2026-69078Alta (8.8)0.41%—3 ago 2026
CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1090 Proxy1
  3. T1090.004 Domain Fronting1
  4. T1185 Browser Session Hijacking1
  5. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.