Vulnerabilities (CVE)

Filtered by vendor Inducer Subscribe
Filtered by product Relate
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-32404 1 Inducer 1 Relate 2025-06-30 N/A 6.0 MEDIUM
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox feature.
CVE-2024-32406 1 Inducer 1 Relate 2025-06-30 N/A 7.5 HIGH
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.
CVE-2024-32407 1 Inducer 1 Relate 2025-06-13 N/A 8.8 HIGH
An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Page Sandbox feature.
CVE-2024-32405 1 Inducer 1 Relate 2025-06-13 N/A 2.6 LOW
Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload to the Answer field of InlineMultiQuestion parameter on Exam function.