Skip to content
Noroxi

TDuckCloud records

7 published records for vendor tduckcloud.

All records

7 records
  • SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

    CriticalCVSS 9.8No exploitEPSS 1%

    tduckcloud · tduckSep 16, 2025

  • CVE-2024-8692
    27Monitor

    TDuckCloud TDuckPro password recovery

    MediumCVSS 6.9No exploitEPSS 1%

    tduckcloud · tduckproSep 11, 2024

  • SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey p

    MediumCVSS 6.5No exploitEPSS 1%

    tduckcloud · tduck-platformJan 12, 2024

  • An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.

    MediumCVSS 6.1No exploitEPSS 0%

    tduckcloud · tduck-platformJul 19, 2023

  • CVE-2025-0558
    21Monitor

    TDuckCloud tduck-platform QueryProThemeRequest.java QueryProThemeRequest sql injection

    MediumCVSS 5.3No exploitEPSS 0%

    tduckcloud · tduck-platformJan 18, 2025

  • TDuckCloud tduck-platform UserFormDataMapper.java UserFormDataMapper sql injection

    LowCVSS 2.1No exploitEPSS 1%

    tduckcloud · tduck-platformJul 20, 2025

  • TDuckCloud tduck-platform manage preHandle improper authorization

    LowCVSS 2.1No exploitEPSS 0%

    tduckcloud · tduck-platformAug 9, 2025