Teedy
Vendor:
First CVE: Jan 10, 2022 · Active for 4 years
8
Total CVEs
More Total CVEs than 87% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Teedy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2022
4 years ago
Most Recent CVE
Oct 16, 2025
284 days ago
CVE Severity & Scoring
Teedy8 CVEs
13%
50%
38%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None2 (25.0%)
Unknown0 (0.0%)
Required6 (75.0%)
Privileges Required
Low3 (37.5%)
High1 (12.5%)
None4 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-46278HIGH Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console. | Oct 7, 2024 | 8.4 | 35 | NO | YES |
CVE-2022-22115CRITICAL In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edi | Jan 10, 2022 | 9.0 | 29 | NO | NO |
CVE-2022-22114CRITICAL In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying t | Jan 10, 2022 | 9.6 | 29 | NO | NO |
CVE-2024-54852CRITICAL When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP injection. Due to improper sanitization of user | Jan 29, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-11853HIGH A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Executing a manipulation can lead | Oct 16, 2025 | 8.1 | 25 | NO | NO |
CVE-2024-54851HIGH Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection. | Jan 29, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-22963HIGH Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin. | Jan 13, 2025 | 7.5 | 23 | NO | NO |
CVE-2023-4892MEDIUM Teedy v1.11 has a vulnerability in its text editor that allows events
to be executed in HTML tags that an attacker could manipulate. Thanks
to this, it is possible to execute mal | Sep 25, 2023 | 4.6 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Teedy
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.11 | 2 | 6.5 | 1.5% | 0 | 1 |