Cerebrate is a threat-intelligence sharing and collaboration platform maintained by the Cerebrate Project, a niche but notably positioned component in the information-sharing infrastructure used by security teams and incident-response communities. The vulnerability profile is concentrated in the single Cerebrate product itself, reflecting its focused scope as a specialized platform rather than a broad portfolio. Live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cerebrate Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28883CRITICAL In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint. | Mar 27, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-26468CRITICAL Cerebrate 1.12 does not properly consider organisation_id during creation of API keys. | Feb 24, 2023 | 9.1 | 27 | NO | NO |
CVE-2025-66385CRITICAL UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit | Nov 28, 2025 | 9.4 | 26 | NO | NO |
CVE-2022-25321MEDIUM An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. | Feb 18, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-25317MEDIUM An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description. | Feb 18, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-25320MEDIUM An issue was discovered in Cerebrate through 1.4. Username enumeration could occur. | Feb 18, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-25318MEDIUM An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups. | Feb 18, 2022 | 4.3 | 18 | NO | NO |
CVE-2023-41908MEDIUM Cerebrate before 1.15 lacks the Secure attribute for the session cookie. | Sep 5, 2023 | 5.3 | 17 | NO | NO |
CVE-2023-41363MEDIUM In Cerebrate 1.14, a vulnerability in UserSettingsController allows authenticated users to change user settings of other users. | Aug 29, 2023 | 4.3 | 16 | NO | NO |
CVE-2022-25319MEDIUM An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled. | Feb 18, 2022 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cerebrate Project.
Media articles that mention a CVE ID that affects a product developed by Cerebrate Project — matched by CVE ID, not by vendor name.