Tad Book3 Project maintains a focused digital publishing application where the observed vulnerability pattern centers on access control and input-handling gaps, including improper authorization, cross-site scripting, and missing authentication for critical functions. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tad Book3 Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41974CRITICAL Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission. | Oct 8, 2021 | 9.1 | 30 | NO | NO |
CVE-2021-41563MEDIUM Tad Book3 editing book function does not filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks. | Oct 8, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tad Book3 Project.
Media articles that mention a CVE ID that affects a product developed by Tad Book3 Project — matched by CVE ID, not by vendor name.