Talkyard is a focused community and discussion platform product with a modest vulnerability footprint centered on application-layer input-handling and session-management issues, including injection weaknesses and insufficient session expiration. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Talkyard over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25981CRITICAL In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an att | Jan 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-25980HIGH In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28- | Nov 11, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Talkyard.
Media articles that mention a CVE ID that affects a product developed by Talkyard — matched by CVE ID, not by vendor name.