TCS-CERT (Thales Cyber Solutions Customer’s CERT)
First CVE: Dec 1, 2025Active for: 1 year
11
CVEs Published
More CVEs Published than 28% of tracked CNAs
5.5
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by TCS-CERT (Thales Cyber Solutions Customer’s CERT) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2025
7 months ago
Most Recent CVE
Jul 15, 2026
9 days ago
Top CVEs
All CVEs published by TCS-CERT (Thales Cyber Solutions Customer’s CERT) as a CNA, regardless of affected vendor or product.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13872CRITICAL Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to per | Dec 2, 2025 | 9.1 | 32 | NO | NO |
CVE-2025-13871HIGH Cross-Site Request Forgery (CSRF) in the resource-management feature of
ObjectPlanet Opinio 7.26 rev12562
allows to upload
files on behalf of the connected users and then acce | Dec 2, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-13829HIGH Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.
Critical information ret | Dec 1, 2025 | 8.6 | 27 | NO | NO |
CVE-2026-9007MEDIUM Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected
Cross-Site Scripting (XSS).
S | Jul 15, 2026 | 5.5 | 25 | NO | NO |
CVE-2026-2344HIGH A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged users.This issue affects Plunet BusinessManager: 10.15.1 | Feb 11, 2026 | 8.6 | 25 | NO | NO |
CVE-2026-2337HIGH A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of the user.This issue affects Plunet BusinessManager: 10.15.1 | Feb 11, 2026 | 8.7 | 25 | NO | NO |
CVE-2026-6501MEDIUM Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup.
This issue affects jOpenD | May 4, 2026 | 5.3 | 24 | NO | NO |
CVE-2026-6500MEDIUM Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data.
This issue affects OpenConcerto: 1.7.5. | May 4, 2026 | 4.8 | 23 | NO | NO |
CVE-2025-13873MEDIUM Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which | Dec 2, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-15479MEDIUM Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platfo | Jan 7, 2026 | 5.4 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA11 CVEs
9%
45%
36%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (18.2%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low7 (63.6%)
High0 (0.0%)
None4 (36.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by TCS-CERT (Thales Cyber Solutions Customer’s CERT) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by TCS-CERT (Thales Cyber Solutions Customer’s CERT) as a CNA — matched by CVE ID, not by organization name.