Known Vulnerabilities for products from Testlink
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Testlink".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-50110 json | 7.5 - HIGH | 2023-12-30 | 2024-01-05 | |
| CVE-2022-35196 json | TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php. | 8.8 - HIGH | 2022-09-20 | 2022-09-21 |
| CVE-2022-35195 json | TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload... | 7.2 - HIGH | 2022-09-16 | 2022-09-17 |
| CVE-2022-35194 json | TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView... | 5.4 - MEDIUM | 2022-09-16 | 2022-09-21 |
| CVE-2022-35193 json | TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php. | 7.2 - HIGH | 2022-09-16 | 2022-09-17 |
| CVE-2020-12274 json | In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on clien... | 9.8 - CRITICAL | 2020-04-27 | 2021-07-21 |
| CVE-2020-12273 json | In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials. | 7.5 - HIGH | 2020-04-27 | 2021-07-21 |
| CVE-2020-8841 json | An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vul... | 8.8 - HIGH | 2020-02-10 | 2020-02-12 |
| CVE-2020-8639 json | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitra... | 8.8 - HIGH | 2020-04-03 | 2021-02-22 |
| CVE-2020-8638 json | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via th... | 9.8 - CRITICAL | 2020-04-03 | 2020-04-06 |
| CVE-2020-8637 json | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php ... | 9.8 - CRITICAL | 2020-04-03 | 2020-04-06 |
| CVE-2019-20381 json | TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists be... | 6.1 - MEDIUM | 2020-01-20 | 2020-01-24 |
| CVE-2019-20107 json | Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL ... | 8.8 - HIGH | 2020-03-05 | 2020-03-07 |
| CVE-2019-19491 json | TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a... | 6.1 - MEDIUM | 2019-12-02 | 2019-12-04 |
| CVE-2019-14471 json | TestLink 1.9.19 has XSS via the error.php message parameter. | 6.1 - MEDIUM | 2019-08-01 | 2019-08-02 |
| CVE-2018-7668 json | TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/att... | 7.5 - HIGH | 2018-03-05 | 2018-03-27 |
| CVE-2018-7466 json | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging contro... | 7.5 - HIGH | 2018-02-25 | 2019-03-05 |
| CVE-2015-7391 json | Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web ... | 6.1 - MEDIUM | 2017-09-26 | 2018-10-09 |
| CVE-2015-7390 json | SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apike... | 9.8 - CRITICAL | 2017-09-26 | 2019-03-11 |
| CVE-2014-8082 json | lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspec... | Not Provided | 2014-10-31 | 2026-05-06 |
Known software with vulnerabilities from Testlink
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Testlink | Testlink | 1.8.0 |