Taguette is a lightweight, open-source qualitative-data-analysis application focused on document annotation and coding workflows, with a modest vulnerability footprint concentrated in the single product. Its observed weakness classes—external control of system configuration, cross-site scripting, and open-redirect flaws—reflect the risks inherent in web-based document processing and user-input handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Taguette over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62527HIGH Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset em | Oct 20, 2025 | 7.1 | 24 | NO | NO |
CVE-2025-67502MEDIUM Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites after auth | Dec 10, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-62528MEDIUM Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for a project member to put JavaScript in na | Oct 20, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Taguette.
Media articles that mention a CVE ID that affects a product developed by Taguette — matched by CVE ID, not by vendor name.