Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tainacan

First CVE: Nov 30, 2023Active for: 3 yearsTotal CVEs: 15
26.5
VTI Score
Low

Tainacan is a focused digital collection and museum-management platform that occupies a niche but specialized position in the cultural-heritage software landscape. Its vulnerability profile centers on a single product and skews toward serious outcomes, with recurring weaknesses in web-application input handling—cross-site scripting and SQL injection—alongside authorization and sensitive-data disclosure issues characteristic of applications managing institutional collections and user access. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tainacan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2023
2 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-42740CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Injection.This issue affects Taina
May 27, 20269.333NONO
CVE-2026-6230HIGH
The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escapin
Jul 8, 20267.530NONO
CVE-2024-30529CRITICAL
Missing Authorization vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.7.
Jun 9, 20249.824NONO
CVE-2025-12746MEDIUM
The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 1.0.0 due to insufficient input s
Nov 21, 20256.122NONO
CVE-2025-47512HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan tainacan allows Path Traversal.This issue affects Tainacan: from n
May 23, 20258.622NONO
CVE-2025-14043MEDIUM
The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is d
Dec 21, 20255.320NONO
CVE-2025-12747MEDIUM
The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content
Nov 21, 20255.320NONO
CVE-2024-7135MEDIUM
The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.
Jul 31, 20246.520NONO
CVE-2024-34794MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.
Jun 3, 20246.120NONO
CVE-2024-1435HIGH
Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.6.
Feb 29, 20247.520NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
67%
20%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (66.7%)
Unknown0 (0.0%)
Required5 (33.3%)
Privileges Required
Low4 (26.7%)
High0 (0.0%)
None11 (73.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tainacan.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tainacan — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tainacan's Products

View all 2 CNAs →

Top CWEs