Squashtest's vulnerability profile centers on its test-management platform Squash TM, a specialized tool for quality assurance and test orchestration deployed in development environments. The observed weakness class reflects credential-handling practices, with disclosures centered on insufficiently protected credentials that are characteristic of authentication and configuration mechanisms in enterprise testing tools. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Squashtest over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16987HIGH Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code. | Sep 13, 2018 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Squashtest.
Media articles that mention a CVE ID that affects a product developed by Squashtest — matched by CVE ID, not by vendor name.