inducer records
5 published records for vendor inducer.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-208 Observable Timing Discrepancy1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-32407No exploit | An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox featinducer · relate · CWE-918 | High8.8 | — | 1.1% | Apr 22, 2024 |
32Monitor | CVE-2026-41588No exploit | RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()inducer · relate · CWE-208 | High8.1 | — | 0.5% | May 8, 2026 |
30Monitor | CVE-2024-32406No exploit | Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code viainducer · relate · CWE-1336 | High7.5 | — | 1.1% | Apr 26, 2024 |
24Monitor | CVE-2024-32404No exploit | Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code viainducer · relate · CWE-94 | Medium6.0 | — | 0.8% | Apr 26, 2024 |
10Monitor | CVE-2024-32405No exploit | Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload tinducer · relate · CWE-79 | Low2.6 | — | 0.5% | Apr 22, 2024 |
- CVE-2024-3240735Monitor
An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feat
HighCVSS 8.8No exploitEPSS 1%inducer · relateApr 22, 2024
- CVE-2026-4158832Monitor
RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()
HighCVSS 8.1No exploitEPSS 0%inducer · relateMay 8, 2026
- CVE-2024-3240630Monitor
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via
HighCVSS 7.5No exploitEPSS 1%inducer · relateApr 26, 2024
- CVE-2024-3240424Monitor
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via
MediumCVSS 6.0No exploitEPSS 1%inducer · relateApr 26, 2024
- CVE-2024-3240510Monitor
Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload t
LowCVSS 2.6No exploitEPSS 1%inducer · relateApr 22, 2024