Tabit's vulnerability profile centers on a single, niche hospitality and restaurant-management platform, where disclosures cluster around access-control and information-handling weaknesses. The exposures recur through authorization bypasses, credential and data-exposure flaws, and injection-oriented input-validation issues typical of web-facing business applications, and a meaningful share of the vendor's vulnerabilities reach critical severity. Defenders deploying this platform should prioritize patches addressing access-control and injection risks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tabit over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34773CRITICAL Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addresses to the DB. This is an example of OWASP:API8 – Injection | Aug 22, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-34772HIGH Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. On | Aug 22, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-34776HIGH Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a specific restaurant, a | Aug 22, 2022 | 7.5 | 23 | NO | NO |
CVE-2022-34775HIGH Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the reservation, and organization. This | Aug 22, 2022 | 7.5 | 23 | NO | NO |
CVE-2022-34770HIGH Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a specif | Aug 22, 2022 | 7.5 | 23 | NO | NO |
CVE-2022-34774MEDIUM Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can modify personal details, such as email addresses and phone nu | Aug 22, 2022 | 5.3 | 19 | NO | NO |
Tabit - arbitrary SMS send on Tabits behalf. The resend OTP API of tabit allows an adversary to send messages on tabits behalf to anyone registered on the system - the API receives | Aug 22, 2022 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tabit.
Media articles that mention a CVE ID that affects a product developed by Tabit — matched by CVE ID, not by vendor name.