All 5 CVE vulnerabilities found in Altair, with AI-generated Chinese analysis, references, and POCs.
Vendor: altair-graphql
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2025-32928 | WordPress Altair theme <= 5.2.2 - PHP Object Injection vulnerability CWE-502 | 9.8 | Critical | 2025-05-19 |
| CVE-2024-12922 | Altair <= 5.2.4 - Unauthenticated Arbitrary Options Update via pp_import_current CWE-862 | 9.8 | Critical | 2025-03-19 |
| CVE-2024-56200 | Uncontrolled Recursion and Asymmetric Resource Consumption in Altair media/file proxy CWE-400 | 8.6 | High | 2024-12-19 |
| CVE-2024-54147 | Altair GraphQL Client's desktop app does not validate HTTPS certificates CWE-295 | 6.8 | Medium | 2024-12-09 |
| CVE-2023-43799 | The Altair Desktop Client Does Not Sanitize External URLs before passing them to the underlying system CWE-20 | 5.0 | Medium | 2023-10-04 |
All 5 known CVE vulnerabilities affecting Altair with full Chinese analysis, references, and POCs where available.