The Missing Link Australia (TML)
First CVE: Oct 31, 2022Active for: 4 years
63
CVEs Published
More CVEs Published than 63% of tracked CNAs
12.6
Avg CVEs / Year
More Avg CVEs / Year than 59% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by The Missing Link Australia (TML) over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2022
3 years ago
Most Recent CVE
Jul 7, 2026
16 days ago
Top CVEs
All CVEs published by The Missing Link Australia (TML) as a CNA, regardless of affected vendor or product.
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57867HIGH MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-fo | Jul 7, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-57871HIGH Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files.
This issue affects MicroRealEstate: thro | Jul 7, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-57869HIGH Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords | Jul 7, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-57868HIGH MicroRealEstate is affected by broken object-level access controls in PDF generator functionality.
This issue affects MicroRealEstate: through 1.0.0-alpha3. | Jul 7, 2026 | 7.1 | 31 | NO | NO |
CVE-2022-40293CRITICAL
The application was vulnerable to a session fixation that could be used hijack accounts.
| Oct 31, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-12223CRITICAL Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and | Aug 20, 2025 | 9.3 | 29 | NO | NO |
CVE-2022-40296CRITICAL
The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and loca | Oct 31, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-40289CRITICAL
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or c | Oct 31, 2022 | 9.0 | 29 | NO | NO |
CVE-2022-40288CRITICAL
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and co | Oct 31, 2022 | 9.0 | 29 | NO | NO |
CVE-2023-26582CRITICAL Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticat | Oct 25, 2023 | 9.1 | 28 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA63 CVEs
32%
40%
29%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network62 (98.4%)
Unknown0 (0.0%)
Physical1 (1.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None46 (73.0%)
Unknown0 (0.0%)
Required16 (25.4%)
Privileges Required
Low19 (30.2%)
High1 (1.6%)
None43 (68.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (63 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by The Missing Link Australia (TML) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by The Missing Link Australia (TML) as a CNA — matched by CVE ID, not by organization name.