← Back

Pattern Insight

pattern_insight

Vendor: Patterninsight • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Patterninsight
1Pattern Insight
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly...Show more
Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages.Show less
1Patterninsight
1Pattern Insight
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the web interface in Pattern Insight 2.3 allows remote authenticated administrators to inject arbitrary web script or HTML via the banner message.
1Patterninsight
1Pattern Insight
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie.
1Patterninsight
1Pattern Insight
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The web interface in Pattern Insight 2.3 allows remote attackers to conduct clickjacking attacks via a FRAME element.
1Patterninsight
1Pattern Insight
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack the authentication of arbitrary users.