testlink records
27 published records for vendor testlink.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.7%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-8639Proof of concept | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uplotestlink · testlink · CWE-434 | High8.8 | — | 15.9% | Apr 3, 2020 |
40Plan | CVE-2020-8637Proof of concept | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_idtestlink · testlink · CWE-89 | Critical9.8 | — | 2.9% | Apr 3, 2020 |
40Plan | CVE-2020-8638No exploit | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency paramtestlink · testlink · CWE-89 | Critical9.8 | — | 1.7% | Apr 3, 2020 |
40Plan | CVE-2007-6006No exploit | TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.testlink · testlink · CWE-287 | Critical10.0 | — | 1.4% | Nov 15, 2007 |
39Monitor | CVE-2015-7390No exploit | SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to testlink · testlink · CWE-89 | Critical9.8 | — | 1.6% | Sep 26, 2017 |
39Monitor | CVE-2020-12274No exploit | In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is testlink · testlink | Critical9.8 | — | 1.2% | Apr 27, 2020 |
37Monitor | CVE-2014-5308Proof of concept | Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) namtestlink · testlink · CWE-89 | Critical9.0 | — | 3.5% | Oct 8, 2014 |
36Monitor | CVE-2019-20107No exploit | Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via thtestlink · testlink · CWE-89 | High8.8 | — | 2.0% | Mar 5, 2020 |
35Monitor | CVE-2020-8841No exploit | An issue was discovered in TestLink 1.9.19.testlink · testlink · CWE-89 | High8.8 | — | 1.4% | Feb 10, 2020 |
35Monitor | CVE-2022-35196No exploit | TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.testlink · testlink · CWE-352 | High8.8 | — | 0.5% | Sep 20, 2022 |
32Monitor | CVE-2018-7466Proof of concept | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGINtestlink · testlink · CWE-94 | High7.5 | — | 6.1% | Feb 25, 2018 |
32Monitor | CVE-2024-46097No exploit | TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section.testlink · testlink · CWE-284 | High8.1 | — | 0.4% | Sep 27, 2024 |
31Monitor | CVE-2014-8081No exploit | lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitratestlink · testlink · CWE-94 | High7.5 | — | 4.2% | Oct 31, 2014 |
30Monitor | CVE-2018-7668No exploit | TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownloadtestlink · testlink · CWE-200 | High7.5 | — | 1.5% | Mar 5, 2018 |
30Monitor | CVE-2020-12273No exploit | In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.testlink · testlink · CWE-311 | High7.5 | — | 0.8% | Apr 27, 2020 |
30Monitor | CVE-2023-50110No exploit | TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.testlink · testlink | High7.5 | — | 0.7% | Dec 30, 2023 |
28Monitor | CVE-2012-0938Weaponized | Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to etestlink · testlink · CWE-89 | Medium6.5 | — | 5.8% | Aug 14, 2014 |
28Monitor | CVE-2022-35195No exploit | TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.phptestlink · testlink | High7.2 | — | 1.3% | Sep 16, 2022 |
28Monitor | CVE-2022-35193No exploit | TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.testlink · testlink · CWE-89 | High7.2 | — | 1.2% | Sep 16, 2022 |
26Monitor | CVE-2012-0939No exploit | Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission testlink · testlink · CWE-89 | Medium6.5 | — | 1.2% | Aug 14, 2014 |
24Monitor | CVE-2019-20381No exploit | TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter.testlink · testlink · CWE-79 | Medium6.1 | — | 1.0% | Jan 20, 2020 |
24Monitor | CVE-2019-14471No exploit | TestLink 1.9.19 has XSS via the error.php message parameter.testlink · testlink · CWE-79 | Medium6.1 | — | 0.9% | Aug 1, 2019 |
24Monitor | CVE-2019-19491No exploit | TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/testlink · testlink · CWE-79 | Medium6.1 | — | 0.8% | Dec 1, 2019 |
24Monitor | CVE-2015-7391No exploit | Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML testlink · testlink · CWE-79 | Medium6.1 | — | 0.8% | Sep 26, 2017 |
24Monitor | CVE-2024-42906No exploit | TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file.testlink · testlink · CWE-79 | Medium6.1 | — | 0.3% | Aug 26, 2024 |
- CVE-2020-863940Plan
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uplo
HighCVSS 8.8Proof of conceptEPSS 16%testlink · testlinkApr 3, 2020
- CVE-2020-863740Plan
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id
CriticalCVSS 9.8Proof of conceptEPSS 3%testlink · testlinkApr 3, 2020
- CVE-2020-863840Plan
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency param
CriticalCVSS 9.8No exploitEPSS 2%testlink · testlinkApr 3, 2020
- CVE-2007-600640Plan
TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 1%testlink · testlinkNov 15, 2007
- CVE-2015-739039Monitor
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to
CriticalCVSS 9.8No exploitEPSS 2%testlink · testlinkSep 26, 2017
- CVE-2020-1227439Monitor
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is
CriticalCVSS 9.8No exploitEPSS 1%testlink · testlinkApr 27, 2020
- CVE-2014-530837Monitor
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) nam
CriticalCVSS 9.0Proof of conceptEPSS 4%testlink · testlinkOct 8, 2014
- CVE-2019-2010736Monitor
Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via th
HighCVSS 8.8No exploitEPSS 2%testlink · testlinkMar 5, 2020
- CVE-2020-884135Monitor
An issue was discovered in TestLink 1.9.19.
HighCVSS 8.8No exploitEPSS 1%testlink · testlinkFeb 10, 2020
- CVE-2022-3519635Monitor
TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
HighCVSS 8.8No exploitEPSS 1%testlink · testlinkSep 20, 2022
- CVE-2018-746632Monitor
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN
HighCVSS 7.5Proof of conceptEPSS 6%testlink · testlinkFeb 25, 2018
- CVE-2024-4609732Monitor
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section.
HighCVSS 8.1No exploitEPSS 0%testlink · testlinkSep 27, 2024
- CVE-2014-808131Monitor
lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitra
HighCVSS 7.5No exploitEPSS 4%testlink · testlinkOct 31, 2014
- CVE-2018-766830Monitor
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload
HighCVSS 7.5No exploitEPSS 1%testlink · testlinkMar 5, 2018
- CVE-2020-1227330Monitor
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
HighCVSS 7.5No exploitEPSS 1%testlink · testlinkApr 27, 2020
- CVE-2023-5011030Monitor
TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.
HighCVSS 7.5No exploitEPSS 1%testlink · testlinkDec 30, 2023
- CVE-2012-093828Monitor
Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to e
MediumCVSS 6.5WeaponizedEPSS 6%testlink · testlinkAug 14, 2014
- CVE-2022-3519528Monitor
TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php
HighCVSS 7.2No exploitEPSS 1%testlink · testlinkSep 16, 2022
- CVE-2022-3519328Monitor
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
HighCVSS 7.2No exploitEPSS 1%testlink · testlinkSep 16, 2022
- CVE-2012-093926Monitor
Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission
MediumCVSS 6.5No exploitEPSS 1%testlink · testlinkAug 14, 2014
- CVE-2019-2038124Monitor
TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter.
MediumCVSS 6.1No exploitEPSS 1%testlink · testlinkJan 20, 2020
- CVE-2019-1447124Monitor
TestLink 1.9.19 has XSS via the error.php message parameter.
MediumCVSS 6.1No exploitEPSS 1%testlink · testlinkAug 1, 2019
- CVE-2019-1949124Monitor
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/
MediumCVSS 6.1No exploitEPSS 1%testlink · testlinkDec 1, 2019
- CVE-2015-739124Monitor
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML
MediumCVSS 6.1No exploitEPSS 1%testlink · testlinkSep 26, 2017
- CVE-2024-4290624Monitor
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file.
MediumCVSS 6.1No exploitEPSS 0%testlink · testlinkAug 26, 2024