VulnSea

ail project has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 6.6 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.6
Publish → KEV
—
Last 90 days
6 prev 0

Products

  • ail framework 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ail project vulnerabilities

CVEs affecting ail project, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-100174Medium· 5.1
today

The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS)

The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript event handlers (e.g…

▾ Sunlitail project · ail frameworkvia NVD
CVE-2026-100172High· 8.5
today

The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message…

The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message…

▾ Twilightail project · ail frameworkvia NVD
CVE-2026-100187Medium· 6.9
today

The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), wit…

The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), wit…

▾ Sunlitail project · ail frameworkvia NVD
CVE-2026-100177Medium· 6.3
today

The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task

The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task. The original code only verified tha…

▾ Sunlitail project · ail frameworkvia NVD
CVE-2026-100176High· 8.5
today

The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS)

The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst views the usernam…

▾ Twilightail project · ail frameworkvia NVD
CVE-2026-100190Medium· 6.3
today

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and screenshot file path…

▾ Sunlitail project · ail frameworkvia NVD
ail project vulnerabilities (CVEs) · VulnSea