{"api_version":"v1","generated_at":"2026-10-08T00:55:00+00:00","product":{"cve_count":8,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-basecamp-trix-860905b051c2","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"trix","next_cursor":null,"observations":[{"affected":"trix: < 2.1.17","affected_versions_present":true,"cve_id":"CVE-2026-73426","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73426","fixed":"2.1.17.","last_modified":"2026-08-18T17:47:02.477Z","patch_url":"https://github.com/basecamp/trix/security/advisories/GHSA-qmpg-8xg6-ph5q","primary_source":"","published":"2026-08-18T14:24:27.542Z"},{"affected":"trix: < 2.1.18","affected_versions_present":true,"cve_id":"CVE-2026-73428","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73428","fixed":"2.1.18.","last_modified":"2026-08-14T18:06:36.864Z","patch_url":"https://github.com/basecamp/trix/security/advisories/GHSA-53g2-mvcc-q9x3","primary_source":"","published":"2026-08-13T22:04:19.121Z"},{"affected":"< 2.1.18","affected_versions_present":true,"cve_id":"CVE-2026-73427","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73427","fixed":"2.1.18.","last_modified":"2026-08-13T13:51:28.767Z","patch_url":"https://github.com/basecamp/trix/security/advisories/GHSA-53p3-c7vp-4mcc","primary_source":"","published":"2026-08-12T20:50:17.434Z"},{"affected":"< 2.1.15","affected_versions_present":true,"cve_id":"CVE-2025-46812","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-46812","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-08T20:00:42.604Z","patch_url":"","primary_source":"","published":"2025-05-08T19:27:22.573Z"},{"affected":"< 2.1.12","affected_versions_present":true,"cve_id":"CVE-2025-21610","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-21610","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-01-03T16:56:23.301Z","patch_url":"","primary_source":"","published":"2025-01-03T16:29:54.939Z"},{"affected":">= 2.0.0, < 2.1.9; >= 1.0.0, < 1.3.3","affected_versions_present":true,"cve_id":"CVE-2024-53847","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53847","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-10T16:15:40.972Z","patch_url":"","primary_source":"","published":"2024-12-09T18:49:37.339Z"},{"affected":"< 2.1.4","affected_versions_present":true,"cve_id":"CVE-2024-43368","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-43368","fixed":"2.1.4.","last_modified":"2024-08-15T15:00:00.907Z","patch_url":"https://github.com/basecamp/trix/security/advisories/GHSA-qm2q-9f3q-2vcv","primary_source":"","published":"2024-08-14T21:12:24.240Z"},{"affected":"< 2.1.1","affected_versions_present":true,"cve_id":"CVE-2024-34341","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-34341","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T02:51:09.811Z","patch_url":"","primary_source":"","published":"2024-05-07T15:13:03.137Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"basecamp"}}
