altumcode CVE Vulnerabilities & Metrics

Focus on altumcode vulnerabilities and metrics.

Last updated: 15 Feb 2026, 23:25 UTC

About altumcode Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with altumcode. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total altumcode CVEs: 3
Earliest CVE date: 12 Jan 2026, 16:16 UTC
Latest CVE date: 28 Jan 2026, 19:16 UTC

Latest CVE reference: CVE-2025-69602

Rolling Stats

30-day Count (Rolling): 2
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical altumcode CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.0

Max CVSS: 0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS altumcode CVEs

These are the five CVEs with the highest CVSS scores for altumcode, sorted by severity first and recency.

All CVEs for altumcode

CVE-2025-69602 altumcode vulnerability CVSS: 0 28 Jan 2026, 19:16 UTC

A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing an attacker who can set or predict a session ID to potentially hijack an authenticated session.

CVE-2025-69601 altumcode vulnerability CVSS: 0 28 Jan 2026, 19:16 UTC

A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write files outside the intended extraction directory. This allows static files (html, js, css, images) file write to unintended locations, or overwriting existing HTML files, potentially leading to content defacement and, in certain deployments, further impact if sensitive files are overwritten.

CVE-2025-66939 altumcode vulnerability CVSS: 0 12 Jan 2026, 16:16 UTC

Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via a crafted favicon file