Talelin maintains a compact set of content-management-system frameworks built on Flask and Spring Boot that appear in modest deployment. The vulnerability footprint reflects application-layer weaknesses recurring across these products: improper access control, cross-site scripting, brute-force resistance, and authorization logic gaps, consistent with the authentication and input-handling demands of web-based CMS platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Talelin over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32430HIGH An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application. | Jul 21, 2022 | 7.5 | 35 | NO | YES |
CVE-2020-18701CRITICAL Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's aut | Aug 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-18698CRITICAL Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/ | Aug 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2024-41600HIGH Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java | Jul 19, 2024 | 7.5 | 22 | NO | NO |
CVE-2020-18699MEDIUM Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/ap | Aug 16, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Talelin.
Media articles that mention a CVE ID that affects a product developed by Talelin — matched by CVE ID, not by vendor name.