Strangebee

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 10
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-63099

    TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints

    Last Modified: Jul 28, 2026
    Published: Jul 17, 2026

    CVE-2026-63098

    TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint

    Last Modified: Jul 28, 2026
    Published: Jul 17, 2026

    CVE-2025-48740

    A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures a privileged user, authenticated with basic authentication.

    Last Modified: Apr 15, 2026
    Published: May 23, 2025

    CVE-2025-48738

    An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows unauthenticated remote attackers to use the password reset feature without limits. This can lead to several consequences, including mailbox storage exhaustion for targeted users, reputation damage to the SMTP server, potentially causing it to be blacklisted, and overload of the SMTP server's outbound mail queue.

    Last Modified: Apr 15, 2026
    Published: May 23, 2025

    CVE-2025-48741

    A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the user's permissions, through a specific API endpoint.

    Last Modified: Apr 15, 2026
    Published: May 23, 2025
    Items Per Page
    Strangebee Vulnerabilities & Security CVEs | CVE-DB