Skip to main content

Vendor/product archive

strangebee / thehive CVEs

Beta · best-effort

5 CVEs tagged to strangebee / thehive1 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-63098

Published Jul 17, 2026

TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-22877

Published Jan 19, 2024

StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious JavaScript c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22876

Published Jan 19, 2024

StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker to upload a malicio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18376

Published Jun 2, 2019

An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1