Known Vulnerabilities for products from Testlink

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Testlink".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-50110 json 7.5 - HIGH 2023-12-30 2024-01-05
CVE-2022-35196 json TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php. 8.8 - HIGH 2022-09-20 2022-09-21
CVE-2022-35195 json TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload... 7.2 - HIGH 2022-09-16 2022-09-17
CVE-2022-35194 json TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView... 5.4 - MEDIUM 2022-09-16 2022-09-21
CVE-2022-35193 json TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php. 7.2 - HIGH 2022-09-16 2022-09-17
CVE-2020-12274 json In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on clien... 9.8 - CRITICAL 2020-04-27 2021-07-21
CVE-2020-12273 json In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials. 7.5 - HIGH 2020-04-27 2021-07-21
CVE-2020-8841 json An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vul... 8.8 - HIGH 2020-02-10 2020-02-12
CVE-2020-8639 json An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitra... 8.8 - HIGH 2020-04-03 2021-02-22
CVE-2020-8638 json A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via th... 9.8 - CRITICAL 2020-04-03 2020-04-06
CVE-2020-8637 json A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php ... 9.8 - CRITICAL 2020-04-03 2020-04-06
CVE-2019-20381 json TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists be... 6.1 - MEDIUM 2020-01-20 2020-01-24
CVE-2019-20107 json Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL ... 8.8 - HIGH 2020-03-05 2020-03-07
CVE-2019-19491 json TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a... 6.1 - MEDIUM 2019-12-02 2019-12-04
CVE-2019-14471 json TestLink 1.9.19 has XSS via the error.php message parameter. 6.1 - MEDIUM 2019-08-01 2019-08-02
CVE-2018-7668 json TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/att... 7.5 - HIGH 2018-03-05 2018-03-27
CVE-2018-7466 json install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging contro... 7.5 - HIGH 2018-02-25 2019-03-05
CVE-2015-7391 json Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web ... 6.1 - MEDIUM 2017-09-26 2018-10-09
CVE-2015-7390 json SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apike... 9.8 - CRITICAL 2017-09-26 2019-03-11
CVE-2014-8082 json lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspec... Not Provided 2014-10-31 2026-05-06

Known software with vulnerabilities from Testlink

Type Vendor Product Version
ApplicationTestlinkTestlink1.8.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report