Altium records
11 published records for vendor altium.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 90.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation1
- CWE-295 Improper Certificate Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-11420No exploit | Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File Readaltium · on-prem enterprise server · CWE-22 | Critical10.0 | — | 0.7% | Jun 5, 2026 |
40Plan | CVE-2026-11414No exploit | Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded Cryptographic Key and Path Traversalaltium · on-prem enterprise server · CWE-22 | Critical10.0 | — | 0.5% | Jun 5, 2026 |
39Monitor | CVE-2025-27378No exploit | SQL Injection in AES Due to Inactive SQL Parsing Configurationaltium · on-prem enterprise server · CWE-20 | Critical9.8 | — | 0.4% | Jan 21, 2026 |
37Monitor | CVE-2026-11419No exploit | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Writealtium · on-prem enterprise server · CWE-22 | Critical9.4 | — | 0.5% | Jun 5, 2026 |
30Monitor | CVE-2025-27380No exploit | HTML Injection Leading to Script Execution in Altium Enterprise Serveraltium · on-prem enterprise server · CWE-79 | High7.6 | — | 0.3% | Jan 21, 2026 |
24Monitor | CVE-2026-1011No exploit | Stored Cross-Site Scripting in Altium Live Support Center Comment Endpointaltium · altium live · CWE-79 | Medium6.1 | — | 0.3% | Jan 15, 2026 |
21Monitor | CVE-2026-1010Proof of concept | Stored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege Escalationaltium · on-prem enterprise server · CWE-79 | Medium5.4 | — | 0.3% | Jan 15, 2026 |
21Monitor | CVE-2026-1009No exploit | Stored Cross-Site Scripting in Altium Live Forum Leading to Cross-Customer Data Exposurealtium · altium live · CWE-79 | Medium5.4 | — | 0.2% | Jan 15, 2026 |
21Monitor | CVE-2026-1008No exploit | Stored Cross-Site Scripting in Altium Live User Profile Fieldsaltium · altium live · CWE-79 | Medium5.4 | — | 0.2% | Jan 15, 2026 |
21Monitor | CVE-2025-27377No exploit | Missing Validation of Self-Signed Certificates in Altium Designer Allows Man-in-the-Middle Attacksaltium · designer · CWE-295 | Medium5.3 | — | 0.2% | Jan 21, 2026 |
18Monitor | CVE-2025-27379No exploit | Stored Cross-Site Scripting in AES BOM Vieweraltium · on-prem enterprise server · CWE-79 | Medium4.6 | — | 0.2% | Jan 21, 2026 |
- CVE-2026-1142040Plan
Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File Read
CriticalCVSS 10.0No exploitEPSS 1%altium · on-prem enterprise serverJun 5, 2026
- CVE-2026-1141440Plan
Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded Cryptographic Key and Path Traversal
CriticalCVSS 10.0No exploitEPSS 0%altium · on-prem enterprise serverJun 5, 2026
- CVE-2025-2737839Monitor
SQL Injection in AES Due to Inactive SQL Parsing Configuration
CriticalCVSS 9.8No exploitEPSS 0%altium · on-prem enterprise serverJan 21, 2026
- CVE-2026-1141937Monitor
Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write
CriticalCVSS 9.4No exploitEPSS 1%altium · on-prem enterprise serverJun 5, 2026
- CVE-2025-2738030Monitor
HTML Injection Leading to Script Execution in Altium Enterprise Server
HighCVSS 7.6No exploitEPSS 0%altium · on-prem enterprise serverJan 21, 2026
- CVE-2026-101124Monitor
Stored Cross-Site Scripting in Altium Live Support Center Comment Endpoint
MediumCVSS 6.1No exploitEPSS 0%altium · altium liveJan 15, 2026
- CVE-2026-101021Monitor
Stored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege Escalation
MediumCVSS 5.4Proof of conceptEPSS 0%altium · on-prem enterprise serverJan 15, 2026
- CVE-2026-100921Monitor
Stored Cross-Site Scripting in Altium Live Forum Leading to Cross-Customer Data Exposure
MediumCVSS 5.4No exploitEPSS 0%altium · altium liveJan 15, 2026
- CVE-2026-100821Monitor
Stored Cross-Site Scripting in Altium Live User Profile Fields
MediumCVSS 5.4No exploitEPSS 0%altium · altium liveJan 15, 2026
- CVE-2025-2737721Monitor
Missing Validation of Self-Signed Certificates in Altium Designer Allows Man-in-the-Middle Attacks
MediumCVSS 5.3No exploitEPSS 0%altium · designerJan 21, 2026
- CVE-2025-2737918Monitor
Stored Cross-Site Scripting in AES BOM Viewer
MediumCVSS 4.6No exploitEPSS 0%altium · on-prem enterprise serverJan 21, 2026