Otale's vulnerability profile centers on its Tale Blog product, a modestly deployed blogging platform where disclosures cluster around authentication and input-handling weaknesses. The recurring issues—improper authentication, code injection, and cross-site scripting—are typical of web applications handling user input and session management; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Otale over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2339HIGH A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs. The manipulation leads to imp | Mar 16, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-2340MEDIUM A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the function saveOptions of the file /options/save of the compon | Mar 16, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Otale.
Media articles that mention a CVE ID that affects a product developed by Otale — matched by CVE ID, not by vendor name.