Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Citeum

First CVE: Jul 5, 2022Active for: 4 yearsTotal CVEs: 22
37.0
VTI Score
Medium

Citeum maintains OpenCTI, a threat intelligence and case-management platform widely used for security operations and intelligence workflows. The vendor's vulnerability footprint, while concentrated in a single product, skews toward serious outcomes with an elevated share reaching critical severity, reflecting the authentication and input-handling demands of a web-based platform with privileged access to sensitive intelligence data. The recurring weakness classes—improper access control, authorization bypass, and cross-site scripting—center on the attack surface presented by web-tier input handling and role-based access logic. Defenders deploying OpenCTI should prioritize updates for this vendor and restrict network exposure of the platform; current severity, exploitation activity, and CVE counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Citeum over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 5, 2022
4 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-27960CRITICAL
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability
May 5, 20269.839NONO
CVE-2026-35210HIGH
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vulnerability in OpenCTI allows an
Jul 8, 20267.132NONO
CVE-2026-35211MEDIUM
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script filter operator i
Jul 8, 20266.529NONO
CVE-2025-61781CRITICAL
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation"
Jan 5, 20269.129NONO
CVE-2025-24977CRITICAL
OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying inf
May 5, 20259.129NONO
CVE-2026-39980HIGH
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. U
Apr 9, 20267.227NONO
CVE-2026-35212MEDIUM
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering of email-me
Jun 2, 20266.126NONO
CVE-2026-21886HIGH
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "IndividualDeletionDeleteMutation
Mar 17, 20268.126NONO
CVE-2026-21887HIGH
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ingestion feature accepts user-sup
Mar 12, 20267.726NONO
CVE-2026-44730HIGH
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a
May 26, 20267.225NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
41%
45%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (81.8%)
Unknown0 (0.0%)
Required4 (18.2%)
Privileges Required
Low10 (45.5%)
High4 (18.2%)
None8 (36.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Citeum.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Citeum — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Citeum's Products

View all 3 CNAs →

Top CWEs