TDuckCloud records
7 published records for vendor tduckcloud.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-266 Incorrect Privilege Assignment1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-57631No exploit | SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload moduletduckcloud · tduck · CWE-89 | Critical9.8 | — | 0.8% | Sep 16, 2025 |
27Monitor | CVE-2024-8692No exploit | TDuckCloud TDuckPro password recoverytduckcloud · tduckpro · CWE-640 | Medium6.9 | — | 0.5% | Sep 11, 2024 |
26Monitor | CVE-2023-51805No exploit | SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey ptduckcloud · tduck-platform · CWE-89 | Medium6.5 | — | 0.6% | Jan 12, 2024 |
24Monitor | CVE-2023-37733No exploit | An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.tduckcloud · tduck-platform · CWE-79 | Medium6.1 | — | 0.5% | Jul 19, 2023 |
21Monitor | CVE-2025-0558No exploit | TDuckCloud tduck-platform QueryProThemeRequest.java QueryProThemeRequest sql injectiontduckcloud · tduck-platform · CWE-74 | Medium5.3 | — | 0.4% | Jan 18, 2025 |
8Monitor | CVE-2025-7888No exploit | TDuckCloud tduck-platform UserFormDataMapper.java UserFormDataMapper sql injectiontduckcloud · tduck-platform · CWE-74 | Low2.1 | — | 0.5% | Jul 20, 2025 |
8Monitor | CVE-2025-8756No exploit | TDuckCloud tduck-platform manage preHandle improper authorizationtduckcloud · tduck-platform · CWE-266 | Low2.1 | — | 0.4% | Aug 9, 2025 |
- CVE-2025-5763139Monitor
SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module
CriticalCVSS 9.8No exploitEPSS 1%tduckcloud · tduckSep 16, 2025
- CVE-2024-869227Monitor
TDuckCloud TDuckPro password recovery
MediumCVSS 6.9No exploitEPSS 1%tduckcloud · tduckproSep 11, 2024
- CVE-2023-5180526Monitor
SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey p
MediumCVSS 6.5No exploitEPSS 1%tduckcloud · tduck-platformJan 12, 2024
- CVE-2023-3773324Monitor
An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.
MediumCVSS 6.1No exploitEPSS 0%tduckcloud · tduck-platformJul 19, 2023
- CVE-2025-055821Monitor
TDuckCloud tduck-platform QueryProThemeRequest.java QueryProThemeRequest sql injection
MediumCVSS 5.3No exploitEPSS 0%tduckcloud · tduck-platformJan 18, 2025
- CVE-2025-78888Monitor
TDuckCloud tduck-platform UserFormDataMapper.java UserFormDataMapper sql injection
LowCVSS 2.1No exploitEPSS 1%tduckcloud · tduck-platformJul 20, 2025
- CVE-2025-87568Monitor
TDuckCloud tduck-platform manage preHandle improper authorization
LowCVSS 2.1No exploitEPSS 0%tduckcloud · tduck-platformAug 9, 2025