v1

latestOpenAPI 3.1.0Apache 2.02026-07-245981,1853.0 MB
Vulnerabilities

Create Multiple Vulnerabilities

Use this API to create multiple new vulnerabilities in the Vulnerability Library.

post/api/controls/v2/vulnerabilities

Request body

orgGroupIdstring uuid required

Organization group identifier that this vulnerability belongs to.

identifierstring required

Unique business identifier for the vulnerability - must be unique within the organization.

namestring required

Name of the vulnerability.

descriptionstring

Detailed description of the vulnerability.

status'Active' | 'Pending' | 'Archived'

Current status of the vulnerability.

attributesobject

Custom attributes associated with this vulnerability, organized as a map of attribute names to their values.

Example request

[
  {
    "orgGroupId": "123e4567-e89b-12d3-a456-426614174000",
    "identifier": "VULN-2025-001",
    "name": "Cross-Site Scripting (XSS) in Web Application",
    "description": "This vulnerability allows attackers to inject malicious client-side scripts into web pages viewed by other users. The vulnerability arises from inadequate validation and sanitization of user input that is subsequently displayed in web pages.",
    "framework": {
      "id": "123e4567-e89b-12d3-a456-426614174000",
      "name": "ISO 27001",
      "nameKey": "framework.key.iso"
    },
    "category": {
      "name": "Financial Category",
      "nameKey": "IM.FinancialCategoryName"
    },
    "status": "Active"
  }
]

Response

Created

Returns a list of added vulnerability identifiers (guid).

idstring[] required

Primary identifier of the created or updated entity, typically a UUID

Example response

{
  "id": [
    "123e4567-e89b-12d3-a456-426614174000",
    "456a4567-e89b-12d3-123e-426614174001"
  ]
}