Patterninsight maintains a focused product line centered on its Pattern Insight analytics or intelligence platform, with observed vulnerabilities clustering around web application input-handling issues including cross-site scripting and cross-site request forgery. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Patterninsight over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4937MEDIUM Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie. | Nov 18, 2012 | 6.8 | 22 | NO | NO |
CVE-2012-4936MEDIUM The web interface in Pattern Insight 2.3 allows remote attackers to conduct clickjacking attacks via a FRAME element. | Nov 18, 2012 | 6.8 | 21 | NO | NO |
CVE-2012-4935MEDIUM Cross-site request forgery (CSRF) vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack the authentication of arbitrary users. | Nov 18, 2012 | 6.8 | 21 | NO | NO |
CVE-2012-4950MEDIUM Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via c | Nov 18, 2012 | 4.3 | 17 | NO | NO |
Cross-site scripting (XSS) vulnerability in the web interface in Pattern Insight 2.3 allows remote authenticated administrators to inject arbitrary web script or HTML via the banne | Nov 18, 2012 | 3.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Patterninsight.
Media articles that mention a CVE ID that affects a product developed by Patterninsight — matched by CVE ID, not by vendor name.