Known Vulnerabilities for Cerebrate by Cerebrate-project
Listed below are 9 of the newest known vulnerabilities associated with "Cerebrate" by "Cerebrate-project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-53912 json | Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow sto... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-53911 json | Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operatio... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-53901 json | Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attemp... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2023-41908 json | Cerebrate before 1.15 lacks the Secure attribute for the session cookie. | 5.3 - MEDIUM | 2023-09-05 | 2023-09-08 |
| CVE-2023-41363 json | In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other user... | 4.3 - MEDIUM | 2023-08-29 | 2023-08-31 |
| CVE-2023-28883 json | In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint. | 9.8 - CRITICAL | 2023-03-27 | 2024-01-09 |
| CVE-2023-26468 json | Cerebrate 1.12 does not properly consider organisation_id during creation of API keys. | 9.1 - CRITICAL | 2023-02-24 | 2023-03-03 |
| CVE-2022-25321 json | An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. | 6.1 - MEDIUM | 2022-02-18 | 2023-12-21 |
| CVE-2022-25320 json | An issue was discovered in Cerebrate through 1.4. Username enumeration could occur. | 5.3 - MEDIUM | 2022-02-18 | 2023-12-21 |
| CVE-2022-25319 json | An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled. | 5.3 - MEDIUM | 2022-02-18 | 2023-12-21 |