Inducer's vulnerability footprint is narrow, concentrated in its Relate product, and characterized by application-layer code-generation and template-handling weaknesses including code injection, cross-site scripting, and template-engine flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inducer over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41588HIGH RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via c | May 8, 2026 | 8.1 | 33 | NO | NO |
CVE-2024-32407HIGH An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature. | Apr 22, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-32406HIGH Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Ex | Apr 26, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-32404MEDIUM Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox | Apr 26, 2024 | 6.0 | 19 | NO | NO |
Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload to the Answer field of InlineMultiQuestio | Apr 22, 2024 | 2.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inducer.
Media articles that mention a CVE ID that affects a product developed by Inducer — matched by CVE ID, not by vendor name.