Relate
Inducer · 8 CVEs
RELATE Vulnerable to Remote Code Execution (RCE) via Insecure Celery Pickle Deserialization
May 27, 2026
RELATE Vulnerable to Stored XSS via Unprivileged User Profile
May 27, 2026
RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()
May 8, 2026
RELATE: Predictable Token Generation in auth.py and exam.py
May 7, 2026
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execu…
Apr 26, 2024
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execu…
Apr 26, 2024
An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to…
Apr 22, 2024
Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges vi…
Apr 22, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-47161 | RELATE Vulnerable to Remote Code Execution (RCE) via Insecure Celery Pickle Deserialization | HIGH | 0.87% | May 27, 2026 |
| CVE-2026-42197 | RELATE Vulnerable to Stored XSS via Unprivileged User Profile | HIGH | 0.44% | May 27, 2026 |
| CVE-2026-41588 | RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key() | CRITICAL | 0.45% | May 8, 2026 |
| CVE-2026-41505 | RELATE: Predictable Token Generation in auth.py and exam.py | HIGH | 0.42% | May 7, 2026 |
| CVE-2024-32406 | Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload… | HIGH | 1.11% | Apr 26, 2024 |
| CVE-2024-32404 | Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload… | MEDIUM | 0.80% | Apr 26, 2024 |
| CVE-2024-32407 | An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature. | HIGH | 1.10% | Apr 22, 2024 |
| CVE-2024-32405 | Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload to the Answer field… | LOW | 0.50% | Apr 22, 2024 |
Showing 1 to 8 of 8 CVEs